Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2023-37710: IoT-Vulns/tenda/fromSetWirelessRepeat at main · FirmRec/IoT-Vulns

Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

CVE
#vulnerability#git
CVE-2023-37711: IoT-Vulns/tenda/saveParentControlInfo at main · FirmRec/IoT-Vulns

Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.

CVE-2023-37712: IoT-Vulns/tenda/fromSetIpBind at main · FirmRec/IoT-Vulns

Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.

CVE-2023-37704: IoT-Vulns/tenda/6901 at main · FirmRec/IoT-Vulns

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

CVE-2023-37705: IoT-Vulns/tenda/6902 at main · FirmRec/IoT-Vulns

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.

CVE-2023-37706: IoT-Vulns/tenda/6903 at main · FirmRec/IoT-Vulns

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.

CVE-2023-32254: ZDI-23-702

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.

CVE-2023-3566: Vulnerability/WALLABAG/NAME-LIMIT.md at main · ctflearner/Vulnerability

A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233359. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3565: Stored XSS via Default session expiration time in teampass

Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-3579: cve/CSRF.md at main · nightcloudos/cve

A vulnerability, which was classified as problematic, has been found in HadSky 7.11.8. Affected by this issue is some unknown functionality of the component User Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-233372.