Show filters
201 Total Results
Displaying 1-10 of 201
Sort by:
Attacker Value
Unknown
CVE-2024-11149
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
0
Attacker Value
Unknown
CVE-2024-11148
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
0
Attacker Value
Unknown
CVE-2024-10933
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
0
Attacker Value
Unknown
CVE-2024-10934
Disclosure Date: November 15, 2024 (last updated November 16, 2024)
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021,
avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
0
Attacker Value
Unknown
CVE-2024-24117
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.
0
Attacker Value
Unknown
CVE-2024-24116
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
0
Attacker Value
Unknown
CVE-2023-52558
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
0
Attacker Value
Unknown
CVE-2023-52557
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
0
Attacker Value
Unknown
CVE-2023-52556
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.
0
Attacker Value
Unknown
CVE-2023-4409
Disclosure Date: August 18, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237512.
0