2041
|
7.5 |
HIGH
Network
dlink
|
dir-823g_firmware
|
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2023-44828
|
2024-09-20 05:35 |
2023-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2042
|
7.5 |
HIGH
Network
mozilla
|
thunderbird firefox firefox_esr
|
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for…
|
NVD-CWE-noinfo
|
CVE-2023-4583
|
2024-09-20 05:35 |
2023-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2043
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating too much private shader memory on mac OS.
*This bug only affects Firef…
|
CWE-120
Classic Buffer Overflow
|
CVE-2023-4582
|
2024-09-20 05:35 |
2023-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2044
|
7.5 |
HIGH
Network
redhat
|
jboss_enterprise_application_platform single_sign-on jboss_fuse process_automation integration_camel_k data_grid build_of_apache_camel_for_spring_boot build_of_apache_camel_-_haw…
|
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method proce…
|
NVD-CWE-noinfo
|
CVE-2024-7885
|
2024-09-20 05:15 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2045
|
- |
|
-
|
-
|
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not …
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-5971
|
2024-09-20 05:15 |
2024-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2046
|
7.5 |
HIGH
Network
loytec
|
linx-212_firmware lvis-3me12-a1_firmware liob-586_firmware
|
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2023-46382
|
2024-09-20 05:15 |
2023-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2047
|
8.2 |
HIGH
Network
loytec
|
linx-212_firmware lvis-3me12-a1_firmware liob-586_firmware
|
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ U…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-46381
|
2024-09-20 05:15 |
2023-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2048
|
7.5 |
HIGH
Network
loytec
|
linx-212_firmware lvis-3me12-a1_firmware liob-586_firmware
|
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2023-46380
|
2024-09-20 05:15 |
2023-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2049
|
7.5 |
HIGH
Network
zoom
|
video_software_development_kit meeting_software_development_kit
|
Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.
|
NVD-CWE-noinfo
|
CVE-2023-36533
|
2024-09-20 05:15 |
2023-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2050
|
7.8 |
HIGH
Local
|
zoom
|
rooms
|
Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
|
NVD-CWE-noinfo
|
CVE-2023-36537
|
2024-09-20 05:15 |
2023-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|