Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-46871: Memory leaks in NewSFDouble scenegraph/vrml_tools.c:300 · Issue #2658 · gpac/gpac

GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.

CVE
#vulnerability#mac#ubuntu#linux#dos#js#git#php#ssl
CVE-2023-49410: TENDA/w30e/tenda_w30e_setIPv6Status/w30e_setIPv6Status.md at main · GD008/TENDA

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.

CVE-2023-49403: TENDA/w30e/tenda_w30e_setFixTools/w30e_setFixTools.md at main · GD008/TENDA

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.

CVE-2023-49999: TENDA/w30e/tenda_w30e_setUmountUSBPartition/w30e_setUmountUSBPartition.md at main · GD008/TENDA

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.

CVE-2023-49402: TENDA/w30e/tenda_w30e_localMsg/w30e_localMsg.md at main · GD008/TENDA

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.

CVE-2023-50002: TENDA/w30e/tenda_w30e_rebootMesh/w30e_rebootMesh.md at main · GD008/TENDA

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.

CVE-2023-50001: TENDA/w30e/tenda_w30e_upgradeMeshOnline/w30e_upgradeMeshOnline.md at main · GD008/TENDA

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.

CVE-2023-50000: TENDA/w30e/tenda_w30e_resetMesh/w30e_resetMesh.md at main · GD008/TENDA

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.

CVE-2023-6588: Devolutions

Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.

CVE-2023-49967: Typecho v1.2.1 XML Blowup Attack DoS vulnerability · Issue #1648 · typecho/typecho

Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.