Show filters
392 Total Results
Displaying 81-90 of 392
Sort by:
Attacker Value
Unknown

CVE-2020-25928

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the "response data length" field of individual DNS answers, which may cause out-of-bounds read/write operations, leading to Information leak, Denial-or-Service, or Remote Code Execution, depending on the context.
Attacker Value
Unknown

CVE-2021-31245

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.
Attacker Value
Unknown

CVE-2021-29247

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
Attacker Value
Unknown

CVE-2021-29246

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.
Attacker Value
Unknown

CVE-2021-29245

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
Attacker Value
Unknown

CVE-2021-29248

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
Attacker Value
Unknown

CVE-2021-29250

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.
Attacker Value
Unknown

CVE-2021-29251

Disclosure Date: April 01, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.
Attacker Value
Unknown

CVE-2021-29249

Disclosure Date: March 26, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
Attacker Value
Unknown

CVE-2021-26788

Disclosure Date: March 08, 2021 (last updated February 22, 2025)
Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an attacker needs to have TCP connectivity to the target system. Receiving a maliciously crafted TCP packet from an unauthenticated endpoint is sufficient to trigger the bug.