Show filters
419 Total Results
Displaying 11-20 of 419
Sort by:
Attacker Value
Unknown

CVE-2024-8521

Disclosure Date: September 07, 2024 (last updated September 07, 2024)
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.8.1 is able to address this issue. The patch is identified as b31002cec6b71ab5f738881806bb546430ec692e. It is recommended to upgrade the affected component.
0
Attacker Value
Unknown

CVE-2024-22472

Disclosure Date: May 07, 2024 (last updated May 07, 2024)
A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all versions of Silicon Labs 500 Series SDK prior to v6.85.2 running on Silicon Labs 500 series Z-wave devices.
0
Attacker Value
Unknown

CVE-2024-29034

Disclosure Date: March 24, 2024 (last updated January 05, 2025)
CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by browsers to be different from what's allowed by `content_type_allowlist`, by providing multiple values separated by commas. This bypassed value can be used to cause XSS. Upgrade to 3.0.7 or 2.2.6.
0
Attacker Value
Unknown

CVE-2023-51395

Disclosure Date: March 07, 2024 (last updated September 26, 2024)
The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2023-6640

Disclosure Date: February 21, 2024 (last updated February 13, 2025)
Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.
Attacker Value
Unknown

CVE-2023-6533

Disclosure Date: February 21, 2024 (last updated February 13, 2025)
Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC Controller v5.54.0, and earlier.
Attacker Value
Unknown

CVE-2023-39444

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop.
Attacker Value
Unknown

CVE-2023-39443

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the prefix copy loop.
Attacker Value
Unknown

CVE-2023-39414

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the right shift operation.
Attacker Value
Unknown

CVE-2023-39413

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the left shift operation.