Show filters
129 Total Results
Displaying 21-30 of 129
Sort by:
Attacker Value
Unknown

CVE-2024-38761

Disclosure Date: August 01, 2024 (last updated February 12, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
Attacker Value
Unknown

CVE-2024-6536

Disclosure Date: July 30, 2024 (last updated July 30, 2024)
The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown

CVE-2024-37484

Disclosure Date: July 09, 2024 (last updated February 11, 2025)
Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
Attacker Value
Unknown

CVE-2024-3332

Disclosure Date: July 03, 2024 (last updated February 04, 2025)
A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
Attacker Value
Unknown

CVE-2024-3077

Disclosure Date: March 29, 2024 (last updated January 24, 2025)
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
Attacker Value
Unknown

CVE-2023-7060

Disclosure Date: March 15, 2024 (last updated February 04, 2025)
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address.
Attacker Value
Unknown

CVE-2023-6881

Disclosure Date: February 29, 2024 (last updated January 24, 2025)
Possible buffer overflow in is_mount_point
Attacker Value
Unknown

CVE-2024-1638

Disclosure Date: February 19, 2024 (last updated January 18, 2025)
The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that LE Secure Connections is used for read/write access, however this is only true when it is combined with other permissions, namely BT_GATT_PERM_READ_ENCRYPT/BT_GATT_PERM_READ_AUTHEN (for read) or BT_GATT_PERM_WRITE_ENCRYPT/BT_GATT_PERM_WRITE_AUTHEN (for write), if these additional permissions are not set (even in secure connections only mode) then the stack does not perform any permission checks on these characteristics and they can be freely written/read.
Attacker Value
Unknown

CVE-2023-6249

Disclosure Date: February 18, 2024 (last updated January 24, 2025)
Signed to unsigned conversion esp32_ipm_send
Attacker Value
Unknown

CVE-2023-5779

Disclosure Date: February 18, 2024 (last updated January 23, 2025)
can: out of bounds in remove_rx_filter function