๐จ CVE-2023-37707
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6904 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37705
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6902 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37704
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6901 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37703
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6907 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37702
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6801 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37701
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6908 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37712
Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.
๐@cveNotify
Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromSetIpBind at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37711
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.
๐@cveNotify
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/saveParentControlInfo at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37710
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
๐@cveNotify
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromSetWirelessRepeat at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37706
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.
๐@cveNotify
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.
๐@cveNotify
GitHub
IoT-Vulns/tenda/6903 at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-32040
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
๐@cveNotify
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
๐@cveNotify
๐จ CVE-2023-32039
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
๐@cveNotify
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
๐@cveNotify
๐จ CVE-2023-37463
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
๐@cveNotify
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
๐@cveNotify
GitHub
Quadratic complexity bugs may lead to a denial of service
### Impact
Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service.
### Proof of concept
Issue 1:
```bash
python...
Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service.
### Proof of concept
Issue 1:
```bash
python...
๐จ CVE-2023-30565
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
๐@cveNotify
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
๐@cveNotify