All CVEs — page 224 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows an attacker to exploit SSRF in Stirling-PDF by targeting unsecured conversion endpoints, leading to potential data exposure.
The flaw allows an attacker to traverse directories and potentially execute arbitrary code by manipulating path parameters in Node-RED's local-filesystem library storage module.
The flaw allows an attacker to execute arbitrary code by manipulating file paths in Structured Text (.st) program files, due to lack of proper validation.
The flaw in microtar allows an attacker to overwrite the 100-byte field of a stack-allocated structure via a long entry name, leading to potential buffer overflow and execution of arbitrary code.
The flaw involves a fixed-size stack buffer in tinyobjloader-c's parsing function, allowing potential overflow if input exceeds 4096 bytes.
The flaw involves an insecure use of strcpy without length checking, leading to potential stack buffer overflow when processing MOCHAD_RFSEC messages in Domoticz.
The flaw allows unauthenticated access to the device's configuration details via the GET /json/cfg endpoint, exposing sensitive information such as network settings and LED configurations.
The flaw in LINUXTCP port of FreeModbus involves an off-by-one error in a bounds check, leading to potential buffer overflow if exploited.
The IoTSharp BlobStorageController.cs lacks proper authorization, allowing unauthenticated attackers to manipulate storage endpoints, leading to potential data breaches and unauthorized access.
The flaw involves an integer overflow in W64 CUE chunk metadata parsing within dr_libs dr_wav.h, leading to potential buffer overflows and data corruption.
The flaw allows any file: URI to pass validation due to an operator-precedence bug, enabling unauthorized access to local files.
The flaw allows memory corruption via uncanceled AIO requests on error, potentially leading to kernel writes into caller-owned buffers.
The flaw allows for OS command injection due to improper neutralization of user-controlled input in project creation, enabling execution of arbitrary commands.
The flaw in nanoMODBUS allows an out-of-bounds stack read, leading to a potential wild-pointer write. This can be exploited by an attacker to gain unauthorized access or cause system instability.
The flaw allows an out-of-bounds write due to improper validation of the object_length field in the Modbus protocol handling function. This can lead to potential code execution or data corruption.
The flaw allows an attacker to perform an out-of-bounds write, leading to potential data corruption or system instability. This is critical because it can be exploited without user interaction and affects the Modbus server-side handle_read_file_record function.
The flaw involves a use-after-free vulnerability in the RDMA/rxe module of the Linux kernel, leading to potential kernel crashes or page-level use-after-free conditions.
The flaw allows unauthenticated clients to read any file accessible by the backend process due to improper URI handling and lack of proper token validation in non-Electron deployments.
The flaw allows remote URLs to be included in Facelet processing, potentially exposing sensitive files. This matters because it can lead to unauthorized access to critical server files.
The flaw allows admin users to upload arbitrary files without validation, posing a significant security risk.
The flaw allows unauthorized modification of database entries through admin handlers without proper authentication or authorization checks, posing a significant security risk.