๐จ CVE-2023-37722
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeUrlFilter.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeUrlFilter.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromSafeUrlFilter/report.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37719
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromP2pListFilter.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromP2pListFilter.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromP2pListFilter/report.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37721
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeMacFilter.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeMacFilter.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromSafeMacFilter/report.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37718
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeClientFilter.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeClientFilter.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromSafeClientFilter/report.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37717
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromDhcpListClient/repot.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37714
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromRouteStatic.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromRouteStatic.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromRouteStatic/report.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37466
vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with `@@species` accessor property allowing attackers to escape the sandbox and run arbitrary code. Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.
๐@cveNotify
vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with `@@species` accessor property allowing attackers to escape the sandbox and run arbitrary code. Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox.
๐@cveNotify
GitHub
Sandbox Escape
In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed, allowing attackers to escape the sandbox and run arbitrary code.
### Impact
Remote Code Execution, assuming the...
### Impact
Remote Code Execution, assuming the...
๐จ CVE-2023-37723
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromqossetting.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromqossetting.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromqossetting/report.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37716
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fromNatStaticSetting/report.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-37715
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function frmL7ProtForm.
๐@cveNotify
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function frmL7ProtForm.
๐@cveNotify
GitHub
IoT-Vulns/tenda/fmL7ProtForm/reprot.md at main ยท FirmRec/IoT-Vulns
This repository contain recurring IoT vulnerabilities found by FirmRec. - FirmRec/IoT-Vulns
๐จ CVE-2023-3668
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
๐@cveNotify
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
๐@cveNotify
๐จ CVE-2022-33324
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V all versions, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU all versions and Mitsubishi Electric Corporation MELIPC Series MI5122-VW all versions allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.
๐@cveNotify
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V all versions, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU all versions and Mitsubishi Electric Corporation MELIPC Series MI5122-VW all versions allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.
๐@cveNotify
๐จ CVE-2023-34241
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that impacts the entire cupsd process.
The exact cause of this issue is the function `httpClose(con->http)` being called in `scheduler/client.c`. The problem is that httpClose always, provided its argument is not null, frees the pointer at the end of the call, only for cupsdLogClient to pass the pointer to httpGetHostname. This issue happens in function `cupsdAcceptClient` if LogLevel is warn or higher and in two scenarios: there is a double-lookup for the IP Address (HostNameLookups Double is set in `cupsd.conf`) which fails to resolve, or if CUPS is compiled with TCP wrappers and the connection is refused by rules from `/etc/hosts.allow` and `/etc/hosts.deny`.
Version 2.4.6 has a patch for this issue.
๐@cveNotify
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that impacts the entire cupsd process.
The exact cause of this issue is the function `httpClose(con->http)` being called in `scheduler/client.c`. The problem is that httpClose always, provided its argument is not null, frees the pointer at the end of the call, only for cupsdLogClient to pass the pointer to httpGetHostname. This issue happens in function `cupsdAcceptClient` if LogLevel is warn or higher and in two scenarios: there is a double-lookup for the IP Address (HostNameLookups Double is set in `cupsd.conf`) which fails to resolve, or if CUPS is compiled with TCP wrappers and the connection is refused by rules from `/etc/hosts.allow` and `/etc/hosts.deny`.
Version 2.4.6 has a patch for this issue.
๐@cveNotify
GitHub
Merge pull request from GHSA-qjgh-5hcq-5f25 ยท OpenPrinting/cups@9809947
Log result of httpGetHostname BEFORE closing the connection
๐จ CVE-2023-3672
Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5.
๐@cveNotify
Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5.
๐@cveNotify
GitHub
XSS mitigation ยท PlaidWeb/webmention.js@3551b66
This change fixes a security issue raised by @tyage and reported by @psmoros,
in which the `p-name` property wasn't being properly entity-escaped, leading
to an XSS injection attack.
As pa...
in which the `p-name` property wasn't being properly entity-escaped, leading
to an XSS injection attack.
As pa...
๐จ CVE-2023-2975
Issue summary: The AES-SIV cipher implementation contains a bug that causes
it to ignore empty associated data entries which are unauthenticated as
a consequence.
Impact summary: Applications that use the AES-SIV algorithm and want to
authenticate empty data entries as associated data can be mislead by removing
adding or reordering such empty entries as these are ignored by the OpenSSL
implementation. We are currently unaware of any such applications.
The AES-SIV algorithm allows for authentication of multiple associated
data entries along with the encryption. To authenticate empty data the
application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with
NULL pointer as the output buffer and 0 as the input buffer length.
The AES-SIV implementation in OpenSSL just returns success for such a call
instead of performing the associated data authentication operation.
The empty data thus will not be authenticated.
As this issue does not affect non-empty associated data authentication and
we expect it to be rare for an application to use empty associated data
entries this is qualified as Low severity issue.
๐@cveNotify
Issue summary: The AES-SIV cipher implementation contains a bug that causes
it to ignore empty associated data entries which are unauthenticated as
a consequence.
Impact summary: Applications that use the AES-SIV algorithm and want to
authenticate empty data entries as associated data can be mislead by removing
adding or reordering such empty entries as these are ignored by the OpenSSL
implementation. We are currently unaware of any such applications.
The AES-SIV algorithm allows for authentication of multiple associated
data entries along with the encryption. To authenticate empty data the
application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with
NULL pointer as the output buffer and 0 as the input buffer length.
The AES-SIV implementation in OpenSSL just returns success for such a call
instead of performing the associated data authentication operation.
The empty data thus will not be authenticated.
As this issue does not affect non-empty associated data authentication and
we expect it to be rare for an application to use empty associated data
entries this is qualified as Low severity issue.
๐@cveNotify
๐จ CVE-2023-20899
VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management.
๐@cveNotify
VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management.
๐@cveNotify
VMware
VMSA-2023-0015
VMware SD-WAN update addresses a bypass authentication vulnerability (CVE-2023-20899)
๐จ CVE-2023-28862
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.
๐@cveNotify
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.
๐@cveNotify
GitLab
[Security][CVE-2023-28862] AuthBasic does not handle failure correctly (#2896) ยท Issues ยท LemonLDAP NG / lemonldap-ng ยท GitLab
Concerned version Version: 2.0.16 Summary The AuthBasic handler works like this:
๐จ CVE-2023-3673
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.
๐@cveNotify
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.
๐@cveNotify
GitHub
[Task]: Improve Admin translation and application logger sorting (#15โฆ ยท pimcore/pimcore@a06ce0a
โฆ303)
* task: improve valid key for translation listing
* task: force the direction to be ASC/DESC since these are the only valid options
* task: quote application logger sorting setting
...
* task: improve valid key for translation listing
* task: force the direction to be ASC/DESC since these are the only valid options
* task: quote application logger sorting setting
...
๐จ CVE-2023-3434
Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows.
This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger.
๐@cveNotify
Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows.
This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger.
๐@cveNotify
๐จ CVE-2023-3433
The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a local denial of service to the application.
๐@cveNotify
The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a local denial of service to the application.
๐@cveNotify
GitLab
Changelog ยท Wiki ยท savoirfairelinux / jami-client-qt ยท GitLab
Client based on Qt for GNU/Linux, macOS and Windows
๐จ CVE-2023-33868
The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.
๐@cveNotify
The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.
๐@cveNotify