π¨ CVE-2023-25078
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
π@cveNotify
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
π@cveNotify
π¨ CVE-2023-23585
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
π@cveNotify
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.
π@cveNotify
π¨ CVE-2023-22435
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
π@cveNotify
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
π@cveNotify
π¨ CVE-2023-29452
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field βAttribution textβ when selected βOtherβ Tile provider.
π@cveNotify
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field βAttribution textβ when selected βOtherβ Tile provider.
π@cveNotify
π¨ CVE-2023-3659
A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=user/manage_user. The manipulation of the argument firstname/middlename leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234013 was assigned to this vulnerability.
π@cveNotify
A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=user/manage_user. The manipulation of the argument firstname/middlename leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234013 was assigned to this vulnerability.
π@cveNotify
π¨ CVE-2023-3658
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-234012.
π@cveNotify
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-234012.
π@cveNotify
Vuldb
CVE-2023-3658: SourceCodester AC Repair and Services System HTTP POST Request sql injection
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. This vulnerability is traded as CVE-2023-3658.
π¨ CVE-2023-25770
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message.
π@cveNotify
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message.
π@cveNotify
π¨ CVE-2023-25178
Controller may be loaded with malicious firmware which could enable remote code execution
π@cveNotify
Controller may be loaded with malicious firmware which could enable remote code execution
π@cveNotify
π¨ CVE-2023-24480
Controller DoS due to stack overflow when decoding a message from the server
π@cveNotify
Controller DoS due to stack overflow when decoding a message from the server
π@cveNotify
π¨ CVE-2023-24474
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
π@cveNotify
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
π@cveNotify
π¨ CVE-2023-3657
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-234011.
π@cveNotify
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-234011.
π@cveNotify
Vuldb
CVE-2023-3657: SourceCodester AC Repair and Services System HTTP POST Request sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. The identification of this vulnerability is CVE-2023-3657.
π¨ CVE-2023-3661
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-234015.
π@cveNotify
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-234015.
π@cveNotify
Vuldb
CVE-2023-3661: SourceCodester AC Repair and Services System sql injection
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This vulnerability is uniquely identified as CVE-2023-3661.
π¨ CVE-2023-3660
A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add_user_modal.php. The manipulation of the argument un leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-234014 is the identifier assigned to this vulnerability.
π@cveNotify
A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add_user_modal.php. The manipulation of the argument un leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-234014 is the identifier assigned to this vulnerability.
π@cveNotify
π¨ CVE-2023-2003
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.
π@cveNotify
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.
π@cveNotify
www.incibe.es
Embedded malicious code vulnerability in Unitronics Vision1210
INCIBE has coordinated the publication of a vulnerability affecting Unitronics' Vision1210 device, a P
π¨ CVE-2023-26597
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller.
π@cveNotify
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller.
π@cveNotify
π¨ CVE-2023-25948
Server information leak of configuration data when an error is generated in response to a specially crafted message.
π@cveNotify
Server information leak of configuration data when an error is generated in response to a specially crafted message.
π@cveNotify
π¨ CVE-2023-26980
** DISPUTED ** PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this because the attack is not feasible: the home launcher will be loaded before any user applications.
π@cveNotify
** DISPUTED ** PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this because the attack is not feasible: the home launcher will be loaded before any user applications.
π@cveNotify
π¨ CVE-2019-14815
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
π@cveNotify
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
π@cveNotify
π¨ CVE-2023-20185
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.
This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites.
Cisco has not released and will not release software updates that address this vulnerability.
π@cveNotify
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.
This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites.
Cisco has not released and will not release software updates that address this vulnerability.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco ACI Multi-Site CloudSec Encryption Information Disclosure Vulnerability
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.
This vulnerability is due to anβ¦
This vulnerability is due to anβ¦
π¨ CVE-2023-35070
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection.This issue affects Web Collection: before 31197.
π@cveNotify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection.This issue affects Web Collection: before 31197.
π@cveNotify
π¨ CVE-2023-31825
An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.
π@cveNotify
An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.
π@cveNotify