Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown

CVE-2024-47609

Disclosure Date: October 01, 2024 (last updated October 02, 2024)
Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.
0
Attacker Value
Unknown

CVE-2022-38266

Disclosure Date: September 09, 2022 (last updated December 19, 2023)
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
Attacker Value
Unknown

CVE-2021-45703

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvParser::<T>::process may read from uninitialized memory locations.
Attacker Value
Unknown

CVE-2021-28022

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.
Attacker Value
Unknown

CVE-2021-28023

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.
Attacker Value
Unknown

CVE-2021-28024

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.
Attacker Value
Unknown

CVE-2020-36281

Disclosure Date: March 12, 2021 (last updated February 22, 2025)
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
Attacker Value
Unknown

CVE-2020-36280

Disclosure Date: March 12, 2021 (last updated February 22, 2025)
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
Attacker Value
Unknown

CVE-2020-36279

Disclosure Date: March 12, 2021 (last updated February 22, 2025)
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
Attacker Value
Unknown

CVE-2020-36278

Disclosure Date: March 12, 2021 (last updated February 22, 2025)
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.