All CVEs — page 24 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw involves a fixed-size stack buffer in tinyobjloader-c's parsing function, allowing potential overflow if input exceeds 4096 bytes.
The flaw involves an insecure use of strcpy without length checking, leading to potential stack buffer overflow when processing MOCHAD_RFSEC messages in Domoticz.
The flaw allows unauthenticated access to the device's configuration details via the GET /json/cfg endpoint, exposing sensitive information such as network settings and LED configurations.
The flaw involves an off-by-one error in the bounds check for LINUXTCP port of FreeModbus, leading to potential buffer overflow. This matters because it can allow attackers to exploit the vulnerability to execute malicious code or cause system crashes.
The IoTSharp BlobStorageController.cs lacks proper authorization, allowing unauthenticated attackers to access sensitive storage operations such as upload, download, list, modify, and delete.
The flaw involves an integer overflow in W64 CUE chunk metadata parsing within dr_libs dr_wav.h, leading to potential buffer overflows and data corruption.
The flaw allows any file: URI to pass validation due to an operator-precedence bug, enabling unauthorized access to local files.
The flaw allows memory corruption via uncanceled AIO requests on error, potentially leading to kernel writes into caller-owned buffers.
The flaw allows for OS command injection due to improper neutralization of user-controlled input in project creation, enabling execution of arbitrary commands.
The flaw involves an out-of-bounds stack read in nanoMODBUS v1.23.0, allowing a wild-pointer write that can lead to severe system vulnerabilities.
The flaw allows an out-of-bounds write due to improper validation of the object_length field in the Modbus protocol handling function. This can lead to potential code execution or data corruption.
The flaw allows an attacker to perform out-of-bounds writes by manipulating Modbus requests, leading to potential code execution or data corruption.
The flaw involves a use-after-free vulnerability in the RDMA/rxe module of the Linux kernel, leading to potential kernel crashes or page-level use-after-free conditions.
The flaw allows unauthenticated clients to read any file accessible by the backend process due to improper URI handling and lack of proper token validation in non-Electron deployments.
The flaw allows remote URLs to be included in Facelet processing, potentially exposing sensitive files. This matters because it can lead to unauthorized access to critical server files.
The flaw allows admin users to upload arbitrary files without validation, posing a significant security risk.
The flaw allows unauthorized modification of database entries through admin handlers without proper authentication or authorization checks, posing a significant security risk.
The flaw is an SQL injection vulnerability due to direct string concatenation in login.php, allowing attackers to bypass authentication by manipulating input parameters.