Search Results (361534 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-35506 1 Triplecross Project 1 Triplecross 2024-11-21 7.5 High
TripleCross v0.1.0 was discovered to contain a stack overflow which occurs because there is no limit to the length of program parameters.
CVE-2022-35505 1 Triplecross Project 1 Triplecross 2024-11-21 7.5 High
A segmentation fault in TripleCross v0.1.0 occurs when sending a control command from the client to the server. This occurs because there is no limit to the length of the output of the executed command.
CVE-2022-35493 1 Wrteam 1 Eshop - Ecommerce \/ Store Website 2024-11-21 6.1 Medium
A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.
CVE-2022-35491 1 Totolink 2 A3002ru, A3002ru Firmware 2024-11-21 9.8 Critical
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
CVE-2022-35490 1 Zammad 1 Zammad 2024-11-21 9.8 Critical
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.
CVE-2022-35489 1 Zammad 1 Zammad 2024-11-21 6.5 Medium
In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned.
CVE-2022-35488 1 Zammad 1 Zammad 2024-11-21 7.5 High
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
CVE-2022-35487 1 Zammad 1 Zammad 2024-11-21 7.5 High
Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abused by an unauthenticated attacker to gain access to attachments, such as emails or attached files.
CVE-2022-35486 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.
CVE-2022-35485 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x703969.
CVE-2022-35484 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.
CVE-2022-35483 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.
CVE-2022-35482 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x65f724.
CVE-2022-35481 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
CVE-2022-35479 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.
CVE-2022-35478 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.
CVE-2022-35477 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe954.
CVE-2022-35476 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbc0b.
CVE-2022-35475 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6e41a8.
CVE-2022-35474 1 Otfcc Project 1 Otfcc 2024-11-21 6.5 Medium
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b544e.