Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-39058: CVE-reports/CVE-2023-39058.md at main · syz913/CVE-reports

An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE
#vulnerability#git
CVE-2023-39043: Home - YK Communications

An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39040: CVE-reports/CVE-2023-39040.md at main · syz913/CVE-reports

An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-39039: A Family Experience Company

An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVE-2023-33831

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2023-41030: Juplink RX4-1500 Hard-coded Credential Vulnerability - Exodus Intelligence

Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.

CVE-2023-4806: Invalid Bug ID

A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.

CVE-2023-4527: Invalid Bug ID

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

CVE-2023-41595: GitHub - vaxilu/x-ui: 支持多协议多用户的 xray 面板

An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.

CVE-2023-42328: peppermint/apps/client/pages/api/auth/[...nextauth].js at 446a20b870bc68157eaafcb7275c289d76bfb29e · Peppermint-Lab/peppermint

An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.