All CVEs — page 228 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The vulnerability involves a double free issue in the Linux kernel's mac80211 module when handling unsolicited broadcast probe responses, leading to potential memory corruption.
This flaw allows an attacker to manipulate a btrfs free space cache header to cause out-of-bounds memory access during loading, potentially leading to kernel crashes or privilege escalation.
This flaw in the Linux kernel's xfrm: iptfs module allows for memory corruption when handling fragmented packets, leading to potential kernel panics.
A stack-based buffer overflow vulnerability exists in Apache Lucy, which could lead to remote code execution if exploited.
The flaw is a memory allocation vulnerability in Apache Lucy that allows for excessive size values, potentially leading to denial of service or other issues. This matters because it can be exploited if an attacker can manipulate input sizes.
The flaw is a deserialization vulnerability in Apache Lucy, allowing attackers to execute arbitrary code. This matters because it can lead to complete system compromise.
Uncontrolled recursion vulnerability in Apache Lucy allows attackers to cause a denial of service by triggering excessive memory consumption.
The vulnerability allows unauthenticated attackers to delete any media attachment in the WordPress media library by exploiting missing capability checks in the `plupload_ajax_delete_file()` function.
This flaw allows unauthenticated attackers to send large HTTP requests that can exhaust memory on the Rancher Manager server, leading to service disruption.
The flaw allows a malicious user to obtain long-lived registration tokens in plaintext, enabling them to register rogue nodes into the Rancher cluster at any time.
The flaw involves improper file path handling in a cookbook example, allowing for potential directory traversal attacks if copied into production code.
The flaw allows unauthorized access to customer data by bypassing company ownership checks in certain methods, enabling potential data exfiltration or modification.
The flaw allows unauthorized access to TwoFA management functions without proper authentication or permission checks, posing a significant security risk.
The flaw allows attackers to upload executable PHP files via a restricted but incomplete blacklist in file names, potentially leading to remote code execution.
The flaw allows unauthenticated attackers to modify post data, including title, content, and status, by exploiting a missing capability check in the `create_post()` function.
The flaw is a blind SQL Injection vulnerability in the TableOn plugin for WordPress, allowing unauthenticated attackers to extract sensitive database information by manipulating the `filter_data[comment_count]` parameter.