Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2024-5187
Disclosure Date: June 06, 2024 (last updated October 24, 2024)
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of system, personal, or application files, thus impacting the integrity and availability of the system. The issue arises from the function's handling of tar file extraction without performing security checks on the paths within the tar file, as demonstrated by the ability to overwrite the `/home/kali/.ssh/authorized_keys` file by specifying an absolute path in the malicious tar file.
0
Attacker Value
Unknown
CVE-2024-27319
Disclosure Date: February 23, 2024 (last updated February 14, 2025)
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
0
Attacker Value
Unknown
CVE-2024-27318
Disclosure Date: February 23, 2024 (last updated February 14, 2025)
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
0
Attacker Value
Unknown
CVE-2022-25882
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
0
Attacker Value
Unknown
CVE-2021-40650
Disclosure Date: June 14, 2022 (last updated October 07, 2023)
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
0
Attacker Value
Unknown
CVE-2021-40649
Disclosure Date: June 14, 2022 (last updated October 07, 2023)
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
0
Attacker Value
Unknown
CVE-2009-4947
Disclosure Date: July 22, 2010 (last updated October 04, 2023)
SQL injection vulnerability in frmLoginPwdReminderPopup.aspx in Q2 Solutions ConnX 4.0.20080606 allows remote attackers to execute arbitrary SQL commands via the txtEmail parameter.
0