Search Results (97909 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-39941 1 Intel 1 System Usage Report For Gameplay 2024-11-21 7.1 High
Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2023-39936 1 Ashlar 1 Graphite 2024-11-21 7.8 High
In Ashlar-Vellum Graphite v13.0.48, the affected application lacks proper validation of user-supplied data when parsing VC6 files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2023-39935 1 Tp-link 2 Archer C5400, Archer C5400 Firmware 2024-11-21 8.0 High
Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
CVE-2023-39930 1 Pingidentity 1 Pingid Radius Pcv 2024-11-21 7.5 High
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.
CVE-2023-39918 1 Saasproject 1 Booking Package 2024-11-21 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions.
CVE-2023-39915 1 Nlnetlabs 1 Routinator 2024-11-21 7.5 High
NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
CVE-2023-39914 1 Nlnetlabs 1 Bcder 2024-11-21 7.5 High
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
CVE-2023-39910 1 Libbitcoin 1 Libbitcoin Explorer 2024-11-21 7.5 High
The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to recover any wallet private keys generated from "bx seed" entropy output and steal funds. (Affected users need to move funds to a secure new cryptocurrency wallet.) NOTE: the vendor's position is that there was sufficient documentation advising against "bx seed" but others disagree. NOTE: this was exploited in the wild in June and July 2023.
CVE-2023-39909 1 Ericsson 1 Network Manager 2024-11-21 8.8 High
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
CVE-2023-39908 1 Yubico 1 Yubihsm 2 Sdk 2024-11-21 7.5 High
The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.
CVE-2023-39902 2 Nxp, U Boot Secondary Program Loader\/spl\/ 6 I.mx 8m, I.mx 8m Mini, I.mx 8m Nano and 3 more 2024-11-21 7 High
A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing unauthenticated software to execute on the target, leading to privilege escalation. This affects i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus.
CVE-2023-39829 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.
CVE-2023-39828 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.
CVE-2023-39827 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.
CVE-2023-39748 2 Tp-link, Tp Link 3 Tl-wr1041n V2, Tl-wr1041n V2 Firmware, Tl-wr1041n 2024-11-21 7.5 High
An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CVE-2023-39745 1 Tp-link 9 Tl-wr841n, Tl-wr841n V8, Tl-wr841n V8 Firmware and 6 more 2024-11-21 7.5 High
TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CVE-2023-39740 1 Linecorp 1 Onigiriya-musubee 2024-11-21 8.2 High
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39739 1 Linecorp 1 Regina Sweets\&bakery 2024-11-21 8.2 High
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39737 1 Linecorp 1 Matsuya 2024-11-21 8.2 High
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39736 1 Linecorp 1 Fukunaga Memberscard 2024-11-21 8.2 High
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.