Show filters
219 Total Results
Displaying 101-110 of 219
Sort by:
Attacker Value
Unknown
CVE-2019-14204
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply.
0
Attacker Value
Unknown
CVE-2019-14200
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply.
0
Attacker Value
Unknown
CVE-2019-14199
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call.
0
Attacker Value
Unknown
CVE-2019-14195
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.
0
Attacker Value
Unknown
CVE-2019-13103
Disclosure Date: July 29, 2019 (last updated November 27, 2024)
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.
0
Attacker Value
Unknown
CVE-2019-11059
Disclosure Date: May 10, 2019 (last updated November 08, 2023)
Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.
0
Attacker Value
Unknown
CVE-2019-11690
Disclosure Date: May 03, 2019 (last updated November 27, 2024)
gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.
0
Attacker Value
Unknown
CVE-2018-3968
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.
0
Attacker Value
Unknown
CVE-2019-7684
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the /video/uploadvideo fileType parameter to change the list of acceptable extensions from jpg,gif,png,jpeg to jpg,gif,png,jsp,jpeg.
0
Attacker Value
Unknown
CVE-2019-7401
Disclosure Date: February 08, 2019 (last updated November 27, 2024)
NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact.
0