Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Very High
CVE-2020-14500
Disclosure Date: August 25, 2020 (last updated February 22, 2025)
Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
0
Attacker Value
Unknown
CVE-2021-42375
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
0
Attacker Value
Unknown
CVE-2021-21707
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.
0
Attacker Value
Unknown
CVE-2021-31338
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privileges and execute own code on the device.
0
Attacker Value
Unknown
CVE-2021-38453
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
Some API functions allow interaction with the registry, which includes reading values as well as data modification.
0
Attacker Value
Unknown
CVE-2021-3707
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.
0
Attacker Value
Unknown
CVE-2020-29022
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3
0
Attacker Value
Unknown
CVE-2021-25310
Disclosure Date: February 02, 2021 (last updated February 22, 2025)
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs in do_upgrade_post in mini_httpd. NOTE: This vulnerability only affects products that are no longer supported by the maintaine
0
Attacker Value
Unknown
CVE-2020-7928
Disclosure Date: November 23, 2020 (last updated February 22, 2025)
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20.
0
Attacker Value
Unknown
CVE-2020-1653
Disclosure Date: July 08, 2020 (last updated February 21, 2025)
On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which can lead to Flexible PIC Concentrator (FPC) crash or the system to crash and restart (vmcore). This issue can be trigged by IPv4 or IPv6 and it is caused only by TCP packets. This issue is not related to any specific configuration and it affects Junos OS releases starting from 17.4R1. However, this issue does not affect Junos OS releases prior to 18.2R1 when Nonstop active routing (NSR) is configured [edit routing-options nonstop-routing]. The number of mbufs is platform dependent. The following command provides the number of mbufs counter that are currently in use and maximum number of mbufs that can be allocated on a platform: user@host> show system buffers 2437/3143/5580 mbufs in use (current/cache/total) Once the device runs out of mbufs, the FPC crashes or the vmcore occurs and the device might become inaccessible requiring a manual restart. This issue affects J…
0