| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges. |
| Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier. |
| IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure. |
| eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering (DDSSQLFilter) allows any participant in a DDS domain to remotely crash other Fast DDS participants by sending a single crafted SEDP `DATA` submessage whose `PID_CONTENT_FILTER_PROPERTY.filterExpression` contains a deeply nested filter expression. Versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3 fix the issue. |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. |
| After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel. |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality. |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
| Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
| Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. |
| Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. |
| Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. |
| Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
| Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
| Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network. |
| An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior. |