All CVEs — page 33 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw is a heap-based buffer overflow in open62541 1.5.5's HistoryRead path when using the default memory backend history database, allowing potential code execution if exploited.
A buffer overflow vulnerability in open62541 v1.5.5 can be exploited by a remote attacker to cause a denial of service through the Discovery/LDS handling process.
A buffer overflow vulnerability in open62541 1.5.5 allows unauthenticated remote attackers to cause a denial of service by sending malformed RegisterServer or RegisterServer2 requests.
The flaw allows out-of-bounds read in open62541 1.5.5, potentially leading to information disclosure. It matters because attackers can exploit this to gain sensitive data.
The flaw allows remote attackers to cause a denial of service by sending crafted requests, impacting availability.
The flaw in open62541 allows a remote attacker to cause a denial of service through heap use-after-free in GDS PushManagement certificate update when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.
The flaw allows an attacker to smuggle arbitrary SIP messages by exploiting unsigned int overflow in Content-Length parsing, bypassing security policies and rate limiting.
A buffer overflow vulnerability exists in OpenSIPS versions 3.4.0-beta to 3.6.5 and 4.0.0-beta due to improper handling of base64 encoding, allowing remote attackers to inject malicious data into adjacent buffers.
The vulnerability allows for command injection via the reload_config function in H3C NX15 V100R017, enabling remote code execution.
The flaw is a PHP object injection vulnerability in MaxSite CMS that allows unauthenticated attackers to execute arbitrary code by passing malicious serialized data through the maxsite_comuser cookie. This matters because it can lead to full system compromise without authentication.
The flaw allows a user with write access to a shared chat folder to delete chats and messages belonging to the folder owner, potentially leading to data loss.
The vulnerability allows a chat participant to craft a regex pattern that can consume significant CPU resources, potentially blocking the event loop and affecting other users.
A flaw in Open WebUI allowed math blocks to cause a stack overflow, rendering them as executable HTML, leading to potential session token theft and account takeover.
The flaw allows authenticated non-admin users to access full Python tool source code, potentially exposing sensitive information like API keys and internal URLs.
The flaw allows automation rules to cause availability issues for other users due to synchronous computation on the event loop.
The flaw allows attackers to execute arbitrary code by placing a shared object on target storage due to incorrect access control in NASA cFS v7.0.1's dynamic application start path component.