Show filters
201 Total Results
Displaying 1-10 of 201
Sort by:
Attacker Value
Unknown

CVE-2024-11149

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
0
Attacker Value
Unknown

CVE-2024-11148

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
0
Attacker Value
Unknown

CVE-2024-10933

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
0
Attacker Value
Unknown

CVE-2024-10934

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
0
Attacker Value
Unknown

CVE-2024-24117

Disclosure Date: October 02, 2024 (last updated November 14, 2024)
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.
Attacker Value
Unknown

CVE-2024-24116

Disclosure Date: October 02, 2024 (last updated November 14, 2024)
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
Attacker Value
Unknown

CVE-2023-52558

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
0
Attacker Value
Unknown

CVE-2023-52557

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
0
Attacker Value
Unknown

CVE-2023-52556

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.
0
Attacker Value
Unknown

CVE-2023-4409

Disclosure Date: August 18, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237512.