Show filters
391 Total Results
Displaying 61-70 of 391
Sort by:
Attacker Value
Unknown
CVE-2023-43132
Disclosure Date: September 25, 2023 (last updated October 08, 2023)
szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain the hash of the administrator password.
0
Attacker Value
Unknown
CVE-2023-28513
Disclosure Date: July 19, 2023 (last updated February 25, 2025)
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397.
0
Attacker Value
Unknown
CVE-2023-37781
Disclosure Date: July 17, 2023 (last updated February 25, 2025)
An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.
0
Attacker Value
Unknown
CVE-2023-37582
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1.
When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as.
It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
0
Attacker Value
Unknown
CVE-2023-35789
Disclosure Date: June 16, 2023 (last updated February 25, 2025)
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.
0
Attacker Value
Unknown
CVE-2023-34494
Disclosure Date: June 12, 2023 (last updated February 25, 2025)
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
0
Attacker Value
Unknown
CVE-2023-34488
Disclosure Date: June 12, 2023 (last updated February 25, 2025)
NanoMQ 0.17.5 is vulnerable to heap-buffer-overflow in the conn_handler function of mqtt_parser.c when it processes malformed messages.
0
Attacker Value
Unknown
CVE-2023-33657
Disclosure Date: June 08, 2023 (last updated February 25, 2025)
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack.
0
Attacker Value
Unknown
CVE-2023-33660
Disclosure Date: June 08, 2023 (last updated February 25, 2025)
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
0
Attacker Value
Unknown
CVE-2023-33658
Disclosure Date: June 08, 2023 (last updated February 25, 2025)
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack.
0