Show filters
154 Total Results
Displaying 81-90 of 154
Sort by:
Attacker Value
Unknown
CVE-2018-20579
Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Contiki-NG before 4.2 has a stack-based buffer overflow in the push function in os/lib/json/jsonparse.c that allows an out-of-bounds write of an '{' or '[' character.
0
Attacker Value
Unknown
CVE-2018-19417
Disclosure Date: November 21, 2018 (last updated November 27, 2024)
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy to input data into a fixed size buffer. The allocated buffer can fit only MQTT_MAX_TOPIC_LENGTH (default 64) bytes, and a length check is missing. This could lead to Remote Code Execution via a stack-smashing attack (overwriting the function return address). Contiki-NG does not separate the MQTT server from other servers and the OS modules, so access to all memory regions is possible.
0
Attacker Value
Unknown
CVE-2018-1000804
Disclosure Date: October 08, 2018 (last updated November 27, 2024)
contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform Remote Code Execution on device using Contiki-NG operating system. This attack appear to be exploitable via Attacker must be able to run malicious AQL code (e.g. via SQL-like Injection attack).
0
Attacker Value
Unknown
CVE-2018-16667
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c while parsing AQL (lvm_register_variable, lvm_set_variable_value, create_intersection, create_union).
0
Attacker Value
Unknown
CVE-2018-16664
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow in lvm_set_type in os/storage/antelope/lvm.c while parsing AQL (lvm_set_op, lvm_set_relation, lvm_set_operand).
0
Attacker Value
Unknown
CVE-2018-16665
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow while parsing AQL in lvm_shift_for_operator in os/storage/antelope/lvm.c.
0
Attacker Value
Unknown
CVE-2018-16663
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/storage/antelope/aql-parser.c while parsing AQL (storage of relations).
0
Attacker Value
Unknown
CVE-2018-16666
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/antelope/aql-lexer.c while parsing AQL (parsing next string).
0
Attacker Value
Unknown
CVE-2018-14849
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
0
Attacker Value
Unknown
CVE-2018-14850
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
0