Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-10965
Disclosure Date: November 07, 2024 (last updated January 05, 2025)
A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The patch is named c9ce39747e0372aaa2157b2b56174914a12c06d8. It is recommended to apply a patch to fix this issue.
0
Attacker Value
Unknown
CVE-2024-10964
Disclosure Date: November 07, 2024 (last updated January 05, 2025)
A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.
0
Attacker Value
Unknown
CVE-2024-44460
Disclosure Date: September 12, 2024 (last updated September 19, 2024)
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
0
Attacker Value
Unknown
CVE-2023-37781
Disclosure Date: July 17, 2023 (last updated October 08, 2023)
An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.
0
Attacker Value
Unknown
CVE-2023-34494
Disclosure Date: June 12, 2023 (last updated October 08, 2023)
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
0
Attacker Value
Unknown
CVE-2023-34488
Disclosure Date: June 12, 2023 (last updated October 08, 2023)
NanoMQ 0.17.5 is vulnerable to heap-buffer-overflow in the conn_handler function of mqtt_parser.c when it processes malformed messages.
0
Attacker Value
Unknown
CVE-2023-33657
Disclosure Date: June 08, 2023 (last updated October 08, 2023)
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack.
0
Attacker Value
Unknown
CVE-2023-33660
Disclosure Date: June 08, 2023 (last updated October 08, 2023)
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
0
Attacker Value
Unknown
CVE-2023-33658
Disclosure Date: June 08, 2023 (last updated October 08, 2023)
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack.
0
Attacker Value
Unknown
CVE-2023-33659
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
0