All CVEs — page 233 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw is a buffer overflow in open62541 1.5.5's attribute reading logic, allowing remote attackers to cause a denial of service. This matters because it can lead to system crashes without proper mitigation.
The flaw allows a remote attacker to cause a denial of service by exploiting UA_Client_getRemoteDataTypes in open62541 versions prior to v.1.5.5, potentially disrupting system operations.
The flaw is a heap-based buffer overflow in open62541 1.5.5's HistoryRead path when using the default memory backend history database, allowing potential code execution if exploited.
A buffer overflow vulnerability in open62541 v1.5.5 can be exploited by a remote attacker to cause a denial of service through the Discovery/LDS handling process.
A buffer overflow vulnerability in open62541 1.5.5 allows unauthenticated remote attackers to cause a denial of service by sending malformed RegisterServer or RegisterServer2 requests.
The flaw allows out-of-bounds read in open62541 1.5.5, potentially leading to information disclosure. It matters because attackers can exploit this to gain sensitive data.
The flaw allows remote attackers to cause a denial of service by sending crafted requests, impacting availability.
The flaw in open62541 allows a remote attacker to cause a denial of service through heap use-after-free in GDS PushManagement certificate update when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.
The flaw allows an attacker to smuggle arbitrary SIP messages by exploiting unsigned int overflow in Content-Length parsing, bypassing security policies and rate limiting.
The flaw is a buffer overflow in the {s.b64encode} string transformation in OpenSIPS, which can lead to corruption of adjacent buffers and potentially remote code execution.
The vulnerability allows for command injection via the reload_config function in H3C NX15 V100R017, enabling remote code execution.
MaxSite CMS is vulnerable to PHP object injection, allowing unauthenticated attackers to execute arbitrary code via a malicious serialized PHP object in the maxsite_comuser cookie.
The flaw allows a user with write access to a shared chat folder to delete chats and messages belonging to the folder owner, potentially leading to data loss.
The vulnerability allows a chat participant to craft a regex pattern that can consume significant CPU resources, potentially blocking the event loop and affecting other users.
The flaw allows a malicious chat message to execute arbitrary scripts in the browser of the viewer, potentially leading to session token theft and account compromise.
The flaw allows authenticated non-admin users to access full Python tool source code, potentially exposing sensitive information like API keys and internal URLs.