Show filters
924 Total Results
Displaying 41-50 of 924
Sort by:
Attacker Value
Unknown
CVE-2023-40459
Disclosure Date: December 04, 2023 (last updated December 09, 2023)
The
ACEManager component of ALEOS 4.16 and earlier does not adequately perform
input sanitization during authentication, which could potentially result in a
Denial of Service (DoS) condition for ACEManager without impairing other router
functions. ACEManager recovers from the DoS condition by restarting within ten
seconds of becoming unavailable.
0
Attacker Value
Unknown
CVE-2023-40458
Disclosure Date: November 29, 2023 (last updated December 05, 2023)
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a
Denial of Service (DoS) condition for ACEManager without impairing
other router functions. This condition is cleared by restarting the
device.
0
Attacker Value
Unknown
CVE-2023-48221
Disclosure Date: November 20, 2023 (last updated November 30, 2023)
wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to versions 9.2.22 and 9.3.5, a remote format string vulnerability could potentially allow an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 9.2.22 & 9.3.5 and is already included on all Wire products. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2023-6174
Disclosure Date: November 16, 2023 (last updated November 29, 2023)
SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file
0
Attacker Value
Unknown
CVE-2023-32502
Disclosure Date: November 09, 2023 (last updated November 16, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions.
0
Attacker Value
Unknown
CVE-2023-46501
Disclosure Date: November 07, 2023 (last updated November 14, 2023)
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
0
Attacker Value
Unknown
CVE-2023-35968
Disclosure Date: October 11, 2023 (last updated October 13, 2023)
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.
0
Attacker Value
Unknown
CVE-2023-35967
Disclosure Date: October 11, 2023 (last updated October 13, 2023)
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the malloc function.
0
Attacker Value
Unknown
CVE-2023-35966
Disclosure Date: October 11, 2023 (last updated October 13, 2023)
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.
0
Attacker Value
Unknown
CVE-2023-35965
Disclosure Date: October 11, 2023 (last updated October 13, 2023)
Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the malloc function.
0