Aggregator
CVE-2023-44417 | D-Link DAP-2622 IPv4 Address stack-based overflow (ZDI-23-1515)
3 months 4 weeks ago
A vulnerability was found in D-Link DAP-2622 and classified as critical. Affected by this issue is some unknown functionality of the component IPv4 Address Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2023-44417. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-44416 | D-Link DAP-2622 Telnet CLI Command command injection (ZDI-23-1514)
3 months 4 weeks ago
A vulnerability was found in D-Link DAP-2622. It has been classified as critical. This affects an unknown part of the component Telnet CLI Command Handler. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2023-44416. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-44433 | Kofax Power PDF PDF AcroForm Annotation out-of-bounds (ZDI-23-1610)
3 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Kofax Power PDF. This issue affects some unknown processing of the component PDF AcroForm Annotation Handler. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2023-44433. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-44437 | Ashlar-Vellum Cobalt uncontrolled search path (ZDI-23-1595)
3 months 4 weeks ago
A vulnerability has been found in Ashlar-Vellum Cobalt and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path.
This vulnerability is known as CVE-2023-44437. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2023-44438 | Ashlar-Vellum Argon uncontrolled search path (ZDI-23-1596)
3 months 4 weeks ago
A vulnerability was found in Ashlar-Vellum Argon and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to uncontrolled search path.
This vulnerability is handled as CVE-2023-44438. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-44439 | Ashlar-Vellum Xenon uncontrolled search path (ZDI-23-1597)
3 months 4 weeks ago
A vulnerability was found in Ashlar-Vellum Xenon. It has been classified as critical. This affects an unknown part. The manipulation leads to uncontrolled search path.
This vulnerability is uniquely identified as CVE-2023-44439. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2023-44440 | Ashlar-Vellum Lithium uncontrolled search path (ZDI-23-1598)
3 months 4 weeks ago
A vulnerability was found in Ashlar-Vellum Lithium. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to uncontrolled search path.
This vulnerability was named CVE-2023-44440. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2023-44441 | GIMP DDS File Parser heap-based overflow (ZDI-23-1592)
3 months 4 weeks ago
A vulnerability was found in GIMP. It has been rated as critical. This issue affects some unknown processing of the component DDS File Parser. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2023-44441. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-44443 | GIMP PSP File Parser integer overflow (ZDI-23-1593)
3 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in GIMP. Affected by this issue is some unknown functionality of the component PSP File Parser. The manipulation leads to integer overflow.
This vulnerability is handled as CVE-2023-44443. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-50226 | Parallels Desktop link following (ZDI-23-1805)
3 months 4 weeks ago
A vulnerability was found in Parallels Desktop. It has been classified as critical. This affects an unknown part. The manipulation leads to link following.
This vulnerability is uniquely identified as CVE-2023-50226. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-50225 | TP-Link TL-WR902AC dm_fillObjByStr stack-based overflow (ZDI-23-1809)
3 months 4 weeks ago
A vulnerability was found in TP-Link TL-WR902AC and classified as critical. Affected by this issue is the function dm_fillObjByStr. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2023-50225. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-50224 | TP-Link TL-WR841N dropbearpwd information disclosure (ZDI-23-1808)
3 months 4 weeks ago
A vulnerability was found in TP-Link TL-WR841N. It has been classified as problematic. This affects an unknown part of the component dropbearpwd. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2023-50224. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
E2EE стирает границы: Android и iOS теперь в одной лодке
3 months 4 weeks ago
GSMA готовит новый стандарт безопасности для всех мобильных устройств.
CNVD漏洞周报2024年第37期
3 months 4 weeks ago
2024年07月22日-2023年07月28日 本周漏洞态势研判情况本周信息安全漏洞威胁整体评价级别为中。
【漏洞通告】VMware vCenter Server缓冲区溢出漏洞(CVE-2024-38812)
3 months 4 weeks ago
CVE-2024-45769 | Red Hat Enterprise Linux 6/7/8/9 Performance Co-Pilot out-of-bounds write
3 months 4 weeks ago
A vulnerability classified as critical was found in Red Hat Enterprise Linux 6/7/8/9. This vulnerability affects unknown code of the component Performance Co-Pilot. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-45769. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-47086 | Apex Softcell LD DP Back Office API Endpoint OTP authentication bypass by assumed-immutable data (CIVN-2024-0296)
3 months 4 weeks ago
A vulnerability classified as problematic has been found in Apex Softcell LD DP Back Office. This affects an unknown part of the component API Endpoint. The manipulation of the argument OTP leads to authentication bypass by assumed-immutable data.
This vulnerability is uniquely identified as CVE-2024-47086. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-47087 | Apex Softcell LD Geo API Endpoint Client ID/DPID/BOID exposure of private personal information to an unauthorized actor (CIVN-2024-0296)
3 months 4 weeks ago
A vulnerability was found in Apex Softcell LD Geo. It has been rated as problematic. Affected by this issue is some unknown functionality of the component API Endpoint. The manipulation of the argument Client ID/DPID/BOID leads to exposure of private personal information to an unauthorized actor.
This vulnerability is handled as CVE-2024-47087. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47089 | Apex Softcell LD Geo API Endpoint integrity check (CIVN-2024-0296)
3 months 4 weeks ago
A vulnerability was found in Apex Softcell LD Geo. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component API Endpoint. The manipulation leads to improper validation of integrity check value.
This vulnerability is known as CVE-2024-47089. The attack can be launched remotely. There is no exploit available.
vuldb.com