π¨ CVE-2020-36278
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
π@cveNotify
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
π@cveNotify
GitHub
Comparing 1.79.0...1.80.0 Β· DanBloomberg/leptonica
Leptonica is an open source library containing software that is broadly useful for image processing and image analysis applications. The official github repository for Leptonica is: danbloomberg/le...
π¨ CVE-2020-36279
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
π@cveNotify
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
π@cveNotify
GitHub
Comparing 1.79.0...1.80.0 Β· DanBloomberg/leptonica
Leptonica is an open source library containing software that is broadly useful for image processing and image analysis applications. The official github repository for Leptonica is: danbloomberg/le...
π¨ CVE-2020-36281
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
π@cveNotify
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
π@cveNotify
GitHub
Comparing 1.79.0...1.80.0 Β· DanBloomberg/leptonica
Leptonica is an open source library containing software that is broadly useful for image processing and image analysis applications. The official github repository for Leptonica is: danbloomberg/le...
π¨ CVE-2015-5349
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
π@cveNotify
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
π@cveNotify
π¨ CVE-2021-37436
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.
π@cveNotify
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.
π@cveNotify
Ars Technica
Thinking about selling your Echo Dotβor any IoT device? Read this first
Deleting data from Echo Dotsβand other IoT devices from Amazon and elsewhereβis hard.
π¨ CVE-2021-36740
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
π@cveNotify
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
π@cveNotify
GitHub
Take content length into account on H/2 request bodies Β· varnishcache/varnish-cache@82b0a62
When receiving H/2 data frames, make sure to take the advertised content
length into account, and fail appropriately if the combined sum of the
data frames does not match the content length.
length into account, and fail appropriately if the combined sum of the
data frames does not match the content length.
π¨ CVE-2021-23413
This affects the package jszip before 3.7.0.
Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.
π@cveNotify
This affects the package jszip before 3.7.0.
Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.
π@cveNotify
GitHub
fix: Use a null prototype object for this.files by MichaelAquilina Β· Pull Request #766 Β· Stuk/jszip
This approach is taken to prevent overriding object methods that would exist on a normal object Object.create({})
π¨ CVE-2021-3663
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
π@cveNotify
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
π@cveNotify
π¨ CVE-2020-28020
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction.
π@cveNotify
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction.
π@cveNotify
π¨ CVE-2021-37460
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37459
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37458
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37457
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37456
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37455
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37454
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37453
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
π@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
π¨ CVE-2021-37452
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
π@cveNotify
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
π@cveNotify
www.nch.com.au
Telephone Conference Calling Software - Free Download
Quickly download this professional telephone conference server to quickly and easily create and use conference calling. All you need is a telephone and the internet.
π¨ CVE-2021-37451
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
π@cveNotify
GitHub
poc/IVM_5.12_XSS.md at main Β· 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.
π¨ CVE-2021-37450
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
π@cveNotify
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
π@cveNotify
GitHub
poc/IVM_5.12_XSS.md at main Β· 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.
π¨ CVE-2021-37439
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
π@cveNotify
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
π@cveNotify
GitHub
poc/Flexiserver_6.00_LFI.md at main Β· 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.