‼ CVE-2023-37438 ‼
📖 Read
via "National Vulnerability Database".
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to  obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-37432 ‼
📖 Read
via "National Vulnerability Database".
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to  obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-34853 ‼
📖 Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32420 ‼
📖 Read
via "National Vulnerability Database".
dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-35309 ‼
📖 Read
via "National Vulnerability Database".
An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-26683 ‼
📖 Read
via "National Vulnerability Database".
A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-37422 ‼
📖 Read
via "National Vulnerability Database".
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-19726 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-48522 ‼
📖 Read
via "National Vulnerability Database".
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-48565 ‼
📖 Read
via "National Vulnerability Database".
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-20145 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in /src/helper.c in Dnsmasq up to and including 2.80 allows attackers to cause a denial of service via function create_helper.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33388 ‼
📖 Read
via "National Vulnerability Database".
dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y📖 Read
via "National Vulnerability Database".
‼ CVE-2022-35206 ‼
📖 Read
via "National Vulnerability Database".
Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34038 ‼
📖 Read
via "National Vulnerability Database".
Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40264 ‼
📖 Read
via "National Vulnerability Database".
NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28072 ‼
📖 Read
via "National Vulnerability Database".
A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40433 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in function ciMethodBlocks::make_block_at in Oracle JDK (HotSpot VM) 11, 17 and OpenJDK (HotSpot VM) 8, 11, 17, allows attackers to cause a denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-40265 ‼
📖 Read
via "National Vulnerability Database".
A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-37433 ‼
📖 Read
via "National Vulnerability Database".
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to  obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3699 ‼
📖 Read
via "National Vulnerability Database".
An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32421 ‼
📖 Read
via "National Vulnerability Database".
dpic 2021.01.01 has a Heap Use-After-Free in thedeletestringbox() function in dpic.y.📖 Read
via "National Vulnerability Database".