CVE Notify
19.5K subscribers
4 photos
226K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2023-37711
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37710
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37707
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37706
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37705
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37704
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37703
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37702
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37701
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-2846
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules allows a remote unauthenticated attacker to cancel the password/keyword setting and login to the affected products by sending specially crafted packets.

๐ŸŽ–@cveNotify
๐Ÿ‘1
๐Ÿšจ CVE-2023-26299
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2021-3804
taro is vulnerable to Inefficient Regular Expression Complexity

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2021-3810
code-server is vulnerable to Inefficient Regular Expression Complexity

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2021-3759
A memory overflow vulnerability was found in the Linux kernelโ€™s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2022-22531
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed or modified.



๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2022-22530
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical information being modified or completely compromise the availability of the application.



๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2022-22529
SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD are using SAP UI5 standard controls, the UI5 framework provides automated output encoding for its standard controls. This output encoding prevents stored malicious user input from being executed when it is reflected in the UI.



๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-34347



?Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.





๐ŸŽ–@cveNotify