Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40568 2023-08-25 N/A N/A
** REJECT ** GitHub has been informed that the requestor is working with another CNA for these vulnerabilities.
CVE-2022-26592 1 Sass-lang 1 Libsass 2023-08-25 N/A 8.8 HIGH
Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.
CVE-2020-35342 1 Gnu 1 Binutils 2023-08-25 N/A 7.5 HIGH
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
CVE-2021-30047 1 Vsftpd Project 1 Vsftpd 2023-08-25 N/A 7.5 HIGH
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
CVE-2021-46179 1 Upx Project 1 Upx 2023-08-25 N/A 6.5 MEDIUM
Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function.
CVE-2021-46174 1 Gnu 1 Binutils 2023-08-25 N/A 7.5 HIGH
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
CVE-2021-32292 1 Json-c Project 1 Json-c 2023-08-25 N/A 9.8 CRITICAL
An issue was discovered in json-c through 0.15-20200726. A stack-buffer-overflow exists in the function parseit located in json_parse.c. It allows an attacker to cause code Execution.
CVE-2021-40211 1 Imagemagick 1 Imagemagick 2023-08-25 N/A 7.5 HIGH
An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.
CVE-2022-25024 1 Vinitkumar 1 Json2xml 2023-08-25 N/A 7.5 HIGH
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
CVE-2022-29654 1 Nasm 1 Netwide Assembler 2023-08-25 N/A 5.5 MEDIUM
Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file.
CVE-2021-40266 1 Freeimage Project 1 Freeimage 2023-08-25 N/A 6.5 MEDIUM
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
CVE-2020-25887 1 Cesanta 1 Mongoose 2023-08-25 N/A 8.8 HIGH
Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.
CVE-2020-22628 1 Libraw 1 Libraw 2023-08-25 N/A 6.5 MEDIUM
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
CVE-2020-22570 1 Memcached 1 Memcached 2023-08-25 N/A 7.5 HIGH
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
CVE-2020-22219 1 Flac Project 1 Flac 2023-08-25 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.
CVE-2020-21687 1 Nasm 1 Netwide Assembler 2023-08-25 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.
CVE-2023-4456 1 Redhat 1 Openshift Logging 2023-08-25 N/A 6.5 MEDIUM
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.
CVE-2020-21722 1 Ogg Video Tools Project 1 Ogg Video Tools 2023-08-25 N/A 7.8 HIGH
Buffer Overflow vulnerability in oggvideotools 0.9.1 allows remote attackers to run arbitrary code via opening of crafted ogg file.
CVE-2020-21723 1 Ogg Video Tools Project 1 Ogg Video Tools 2023-08-25 N/A 5.5 MEDIUM
A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.
CVE-2020-21724 1 Ogg Video Tools Project 1 Ogg Video Tools 2023-08-25 N/A 7.8 HIGH
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
CVE-2020-21896 1 Artifex 1 Mupdf 2023-08-25 N/A 5.5 MEDIUM
A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file.
CVE-2023-40352 1 Mcafee 1 Safe Connect 2023-08-25 N/A 7.2 HIGH
McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.
CVE-2020-27418 1 Fedoraproject 1 Fedora Linux Kernel 2023-08-25 N/A 7.5 HIGH
A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
CVE-2021-40262 1 Freeimage Project 1 Freeimage 2023-08-25 N/A 6.5 MEDIUM
A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp.
CVE-2020-21679 1 Graphicsmagick 1 Graphicsmagick 2023-08-25 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.
CVE-2021-40265 1 Freeimage Project 1 Freeimage 2023-08-25 N/A 8.8 HIGH
A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.
CVE-2021-40264 1 Freeimage Project 1 Freeimage 2023-08-25 N/A 6.5 MEDIUM
NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.
CVE-2020-21685 1 Nasm 1 Netwide Assembler 2023-08-25 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.
CVE-2023-4373 1 Devolutions 1 Remote Desktop Manager 2023-08-25 N/A 9.8 CRITICAL
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.
CVE-2023-4434 1 Hamza417 1 Inure 2023-08-25 N/A 6.1 MEDIUM
Missing Authorization in GitHub repository hamza417/inure prior to build88.
CVE-2020-26652 1 Realtek 2 Rtl8812au, Rtl8812au Firmware 2023-08-25 N/A 7.5 HIGH
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
CVE-2023-4417 2 Devolutions, Microsoft 2 Remote Desktop Manager, Windows 2023-08-25 N/A 6.5 MEDIUM
Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.
CVE-2020-22916 1 Tukaani 1 Xz 2023-08-25 N/A 5.5 MEDIUM
An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of crafted file.
CVE-2023-40796 2023-08-25 N/A N/A
Phicomm k2 v22.6.529.216 is vulnerable to command injection.
CVE-2020-11711 2023-08-25 N/A N/A
An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious HTML content in order to execute JavaScript inside a victim's browser. This results in a stored XSS on the authentication interface of the admin panel. Moreover, an unsecured authentication form is present on the authentication interface of the SSL VPN captive portal. Users are allowed to save their credentials inside the browser. If an administrator saves his credentials through this unsecured form, these credentials could be stolen via the stored XSS on the admin panel without user interaction. Another possible exploitation would be modification of the authentication form of the admin panel into a malicious form.
CVE-2023-4534 2023-08-25 N/A N/A
A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is an unknown function of the file /fusion/portal/action/Link. The manipulation of the argument link leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238026 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-4452 2023-08-25 N/A N/A
Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2020-22218 1 Libssh2 1 Libssh2 2023-08-25 N/A 7.5 HIGH
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.
CVE-2023-38906 1 Tp-link 3 Tapo, Tapo L530e, Tapo L530e Firmware 2023-08-25 N/A 6.5 MEDIUM
An issue in TPLink Smart bulb Tapo series L530 v.1.0.0 and Tapo Application v.2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.
CVE-2023-38908 1 Tp-link 3 Tapo, Tapo L530e, Tapo L530e Firmware 2023-08-25 N/A 6.5 MEDIUM
An issue in TPLink Smart bulb Tapo series L530 v.1.0.0 and Tapo Application v.2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.
CVE-2023-38909 1 Tp-link 3 Tapo, Tapo L530e, Tapo L530e Firmware 2023-08-25 N/A 6.5 MEDIUM
An issue in TPLink Smart bulb Tapo series L530 v.1.0.0 and Tapo Application v.2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.
CVE-2020-22217 1 C-ares 1 C-ares 2023-08-25 N/A 9.8 CRITICAL
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
CVE-2023-4435 1 Hamza417 1 Inure 2023-08-25 N/A 5.5 MEDIUM
Improper Input Validation in GitHub repository hamza417/inure prior to build88.
CVE-2020-21890 1 Artifex 1 Ghostscript 2023-08-25 N/A 7.8 HIGH
Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.
CVE-2020-21710 1 Artifex 1 Ghostscript 2023-08-25 N/A 5.5 MEDIUM
A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.
CVE-2020-18831 1 Exiv2 1 Exiv2 2023-08-25 N/A 7.8 HIGH
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.
CVE-2023-3936 1 Adenion 1 Blog2social 2023-08-25 N/A 6.1 MEDIUM
The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-3667 1 Bitapps 1 Bit Assist 2023-08-25 N/A 4.8 MEDIUM
The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2020-18232 1 Hdfgroup 1 Hdf5 2023-08-25 N/A 8.8 HIGH
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
CVE-2023-3604 1 Wpexpertsio 1 Change Wp Admin Login 2023-08-25 N/A 7.5 HIGH
The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.