๐จ CVE-2021-25758
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to code execution.
๐@cveNotify
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to code execution.
๐@cveNotify
The JetBrains Blog
JetBrains Blog: The Drive to Develop
Developer Tools for Professionals and Teams
๐จ CVE-2020-28895
In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
๐@cveNotify
In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
๐@cveNotify
Windriver
CVE-2020-28895 - Wind River Support Network
integer overflow in calloc
๐จ CVE-2020-13582
A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
๐@cveNotify
A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
๐@cveNotify
๐จ CVE-2021-3193
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
๐@cveNotify
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
๐@cveNotify
Nagios Enterprises
Security Disclosures | Nagios Enterprises
View disclosed security vulnerabilities and CVEs affecting Nagios solutions including Nagios XI, Log Server, Network Analyzer, Fusion, and Core. Find remediation steps, patches, and security updates to protect your monitoring infrastructure.
๐จ CVE-2020-29538
Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.
๐@cveNotify
Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.
๐@cveNotify
Rsa
RSA-2020-07: Archer, An RSA Business, Update fo... | RSA Link
RSA Identifier: RSA-2020-07 CVE Identifier: CVE-2020-29537, CVE-2020-29536, CVE-2020-29535, CVE-2020-29538 Severity: Medium Severity Rating: See below for
๐จ CVE-2021-1353
A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak that occurs during packet processing. An attacker could exploit this vulnerability by sending a series of crafted IPv4 packets through an affected device. A successful exploit could allow the attacker to exhaust the available memory and cause an unexpected restart of the npusim process, leading to a DoS condition on the affected device.
๐@cveNotify
A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak that occurs during packet processing. An attacker could exploit this vulnerability by sending a series of crafted IPv4 packets through an affected device. A successful exploit could allow the attacker to exhaust the available memory and cause an unexpected restart of the npusim process, leading to a DoS condition on the affected device.
๐@cveNotify
Cisco
Cisco Security Advisory: Cisco StarOS IPv4 Denial of Service Vulnerability
A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to a memory leak that occurs during packet processing.โฆ
The vulnerability is due to a memory leak that occurs during packet processing.โฆ
๐จ CVE-2020-8585
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
๐@cveNotify
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
๐@cveNotify
Netapp
CVE-2020-8585 Sensitive Information Disclosure Vulnerability in OnCommand Unified Manager Core Package | NetApp Product Security
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
๐จ CVE-2020-23522
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
๐@cveNotify
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
๐@cveNotify
Packetstormsecurity
Pixelimity 1.0 Cross Site Request Forgery โ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
๐จ CVE-2021-3156
Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
๐@cveNotify
Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
๐@cveNotify
packetstorm.news
Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers
๐จ CVE-2020-36226
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
๐@cveNotify
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
๐@cveNotify
๐จ CVE-2019-17517
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 5.0.4 for DA14580/1/2/3 devices does not properly restrict the L2CAP payload length, allowing attackers in radio range to cause a buffer overflow via a crafted Link Layer packet.
๐@cveNotify
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 5.0.4 for DA14580/1/2/3 devices does not properly restrict the L2CAP payload length, allowing attackers in radio range to cause a buffer overflow via a crafted Link Layer packet.
๐@cveNotify
๐จ CVE-2020-13858
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.
๐@cveNotify
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.
๐@cveNotify
Mofinetwork
Download
Download - Products Accessories ecommerce, open source, shop, online shopping
๐จ CVE-2020-15835
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the private key can remotely authenticate to the management interface as root.
๐@cveNotify
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the private key can remotely authenticate to the management interface as root.
๐@cveNotify
Mofinetwork
Download
Download - Products Accessories ecommerce, open source, shop, online shopping
๐จ CVE-2020-13856
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.
๐@cveNotify
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.
๐@cveNotify
Mofinetwork
Download
Download - Products Accessories ecommerce, open source, shop, online shopping
๐จ CVE-2020-27222
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.
๐@cveNotify
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.
๐@cveNotify
๐จ CVE-2021-26307
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the processor does not support the CPUID instruction, which is unsound and causes a deterministic crash.
๐@cveNotify
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the processor does not support the CPUID instruction, which is unsound and causes a deterministic crash.
๐@cveNotify
rustsec.org
RUSTSEC-2021-0013: raw-cpuid: Soundness issues in `raw-cpuid` โบ RustSec Advisory Database
Undefined behavior in asstring methods VendorInfoasstring, SoCVendorBrandasstring, and ExtendedFunctionInfoprocessorbrandstring construct byte slices using stdslicefromrawparts, with data coming from reprRust structs. This is always undefined behavior. Seeโฆ
๐จ CVE-2021-26306
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() methods.
๐@cveNotify
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() methods.
๐@cveNotify
rustsec.org
RUSTSEC-2021-0013: raw-cpuid: Soundness issues in `raw-cpuid` โบ RustSec Advisory Database
Undefined behavior in asstring methods VendorInfoasstring, SoCVendorBrandasstring, and ExtendedFunctionInfoprocessorbrandstring construct byte slices using stdslicefromrawparts, with data coming from reprRust structs. This is always undefined behavior. Seeโฆ
๐จ CVE-2021-3185
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
๐@cveNotify
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
๐@cveNotify
๐จ CVE-2020-21176
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
๐@cveNotify
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
๐@cveNotify
blog.jiguang.xyz
thinkjs - sqlๆณจๅ
ฅๆผๆดๅๆ ยท ๆๅ
- ๅ่งๅทฒๆฏๆ
ไบบ
Vulnerability Report: Thinkjs Blind SQL Injection ๆฌๆๆกฃๆ่ฟฐไบThinkjs project็ไธไธช็ฒๆณจๆผๆด๏ผ็ฑไบๅ
ณ็ณปๆฐๆฎๅบไธญmodel.increment(field, step) ๅ model.decrement(field, step)ๅฝๆฐๅฏนstep็ๅๆฐ็ผบๅฐๆฃๆฅ๏ผๆถๆ็ๅๆฐๅฏไปฅๅฏผ่ด็จๅบๅจๅค
๐จ CVE-2020-20289
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
๐@cveNotify
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
๐@cveNotify
๐จ CVE-2021-3291
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
๐@cveNotify
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
๐@cveNotify
GitHub
GitHub - MucahitSaratar/zencart_auth_rce_poc
Contribute to MucahitSaratar/zencart_auth_rce_poc development by creating an account on GitHub.