Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-38866: my_iot_vul/COMFAST/CF-XR11/Command_Inject2 at main · TTY-flag/my_iot_vul

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.

CVE
#vulnerability#web#git
CVE-2023-38864: my_iot_vul/COMFAST/CF-XR11/Command_Inject3 at main · TTY-flag/my_iot_vul

An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.

CVE-2023-38401

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow local users to elevate privileges. Successful exploitation could allow execution of arbitrary code with NT AUTHORITY\SYSTEM privileges on the operating system.

CVE-2023-38861: my_iot_vul/WAVLINK/WL-WN575A3 at main · TTY-flag/my_iot_vul

An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.

CVE-2023-38862: my_iot_vul/COMFAST/CF-XR11/Command_Inject1 at main · TTY-flag/my_iot_vul

An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.

CVE-2023-38863: my_iot_vul/COMFAST/CF-XR11/Command_Inject4 at main · TTY-flag/my_iot_vul

An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.

CVE-2023-38865: my_iot_vul/COMFAST/CF-XR11/Command_Inject5 at main · TTY-flag/my_iot_vul

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.

CVE-2023-4358

Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2023-2312: Stable Channel Update for Desktop

Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-4356

Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)