Show filters
81 Total Results
Displaying 51-60 of 81
Sort by:
Attacker Value
Unknown

CVE-2022-22825

Disclosure Date: January 10, 2022 (last updated October 07, 2023)
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Attacker Value
Unknown

CVE-2022-22824

Disclosure Date: January 10, 2022 (last updated October 07, 2023)
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Attacker Value
Unknown

CVE-2022-22823

Disclosure Date: January 10, 2022 (last updated October 07, 2023)
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Attacker Value
Unknown

CVE-2022-22822

Disclosure Date: January 10, 2022 (last updated October 07, 2023)
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Attacker Value
Unknown

CVE-2021-46143

Disclosure Date: January 06, 2022 (last updated October 07, 2023)
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
Attacker Value
Unknown

CVE-2021-45960

Disclosure Date: January 01, 2022 (last updated October 07, 2023)
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
Attacker Value
Unknown

CVE-2021-41991

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Attacker Value
Unknown

CVE-2021-37190

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.
Attacker Value
Unknown

CVE-2021-37193

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).
Attacker Value
Unknown

CVE-2021-37191

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.