Show filters
40 Total Results
Displaying 21-30 of 40
Sort by:
Attacker Value
Unknown

CVE-2022-21668

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a requirements.txt file, which will cause victims who use pipenv to install the requirements file to download dependencies from a package index server controlled by the attacker. By embedding malicious code in packages served from their malicious index server, the attacker can trigger arbitrary remote code execution (RCE) on the victims' systems. If an attacker is able to hide a malicious `--index-url` option in a requirements file that a victim installs with pipenv, the attacker can embed arbitrary malicious code in packages served from their malicious index server that will be executed on the victim's host during installation (remote code execution/RCE). When pip installs from a source distribution, any code in the setup.py is executed by t…
Attacker Value
Unknown

CVE-2022-0174

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.
Attacker Value
Unknown

CVE-2021-44158

Disclosure Date: January 03, 2022 (last updated February 23, 2025)
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.
Attacker Value
Unknown

CVE-2021-45972

Disclosure Date: January 01, 2022 (last updated February 23, 2025)
The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside of the allocated buffer with arbitrary data.
Attacker Value
Unknown

CVE-2021-45462

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
Attacker Value
Unknown

CVE-2021-21951

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution.
Attacker Value
Unknown

CVE-2021-21950

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted network packet can lead to code execution.
Attacker Value
Unknown

CVE-2021-31345

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on a user-defined applications that runs on top of the UDP protocol. (FSMD-2021-0006)
Attacker Value
Unknown

CVE-2021-31346

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). The total length of an ICMP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on the network buffer organization in memory. (FSMD-2021-0007)
Attacker Value
Unknown

CVE-2021-3581

Disclosure Date: September 04, 2021 (last updated February 23, 2025)
Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Length Value (CWE-805). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8q65-5gqf-fmw5