All CVEs — page 52 of 62
The complete archive, 25 per page, newest first. 1530 records. Search instead.
This vulnerability allows remote attackers to exploit a stack-based buffer overflow in UTT HiPER 1250GW versions up to v3.2.7-210907-180535 by manipulating the tempName argument, leading to potential code execution or system compromise.
The vulnerability allows for a stack-based buffer overflow through improper use of strcpy in UTT HiPER 1250GW firmware versions up to 3.2.7-210907-180535, enabling remote code execution.
The vulnerability allows for SQL injection through manipulation of the keyid argument in the logindojojs file, enabling remote attackers to exploit it for unauthorized access or data theft.
The vulnerability allows for SQL injection through manipulation of the FilterString argument in the GetStoredClassByFilter function, enabling remote code execution.
The flaw allows buffer overflow by concatenating URI components without bounds checking, leading to corruption of global data and deterministic alteration of server behavior.
The flaw allows admin-privileged attackers to probe internal network resources by submitting arbitrary URLs without proper validation, potentially reading sensitive information from cloud metadata services and internal APIs.
The flaw allows authenticated non-admin users to manage server-wide embedding backend configuration, leading to plaintext transmission of sensitive data or denial of service.
The flaw allows session fixation attacks due to un invalidated sessions on login in Ghost Admin versions from 2.2.0 to 6.54.1, posing a medium security risk.
The vulnerability allows a staff user to write files outside the intended directory via custom themes, potentially altering system behavior.
The flaw is a buffer overflow in open62541 1.5.5's attribute reading logic, allowing remote attackers to cause a denial of service. This matters because it can lead to system crashes without proper mitigation.
The flaw allows a remote attacker to cause a denial of service by exploiting UA_Client_getRemoteDataTypes in open62541 versions prior to v.1.5.5, potentially disrupting system operations.