Show filters
1,078 Total Results
Displaying 91-100 of 1,078
Sort by:
Attacker Value
Unknown
CVE-2023-5180
Disclosure Date: December 26, 2023 (last updated January 05, 2024)
An issue was discovered in Open Design Alliance
Drawings SDK before 2024.12. A corrupted value of number
of sectors used by the Fat structure in a crafted DGN file leads to an
out-of-bounds write. An attacker can leverage this vulnerability to execute
code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-6562
Disclosure Date: December 20, 2023 (last updated December 29, 2023)
JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.
0
Attacker Value
Unknown
CVE-2023-4489
Disclosure Date: December 14, 2023 (last updated September 27, 2024)
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.
0
Attacker Value
Unknown
CVE-2023-6542
Disclosure Date: December 12, 2023 (last updated December 19, 2023)
Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to arbitrary URL including application deep links on the device.
0
Attacker Value
Unknown
CVE-2023-5179
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
0
Attacker Value
Unknown
CVE-2023-41096
Disclosure Date: October 26, 2023 (last updated September 26, 2024)
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules)
allows potential modification or extraction of network credentials stored in flash.
This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.
0
Attacker Value
Unknown
CVE-2023-41095
Disclosure Date: October 26, 2023 (last updated September 26, 2024)
Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash.
This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.
0
Attacker Value
Unknown
CVE-2023-45825
Disclosure Date: October 19, 2023 (last updated October 28, 2023)
ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (implementation of interface Credentials it may leak into logs. This happens because this object could be serialized into an error message using `fmt.Errorf("something went wrong (credentials: %q)", credentials)` during connection to the YDB server. If such logging occurred, a malicious user with access to logs could read sensitive information (i.e. credentials) information and use it to get access to the database. ydb-go-sdk contains this problem in versions from v3.48.6 to v3.53.2. The fix for this problem has been released in version v3.53.3. Users are advised to upgrade. Users unable to upgrade should implement the `fmt.Stringer` interface in your custom credentials type with explicit stringify of object state.
0
Attacker Value
Unknown
CVE-2023-36566
Disclosure Date: October 10, 2023 (last updated October 14, 2023)
Microsoft Common Data Model SDK Denial of Service Vulnerability
0
Attacker Value
Unknown
CVE-2023-36415
Disclosure Date: October 10, 2023 (last updated October 14, 2023)
Azure Identity SDK Remote Code Execution Vulnerability
0