| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16726 | Med | 0.44 | — | 0.00 | Sep 14, 2026 | Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows. | ||
| CVE-2023-46273 | Hig | 0.57 | 8.8 | 0.00 | Sep 14, 2026 | Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send. | ||
| CVE-2023-46035 | Med | 0.31 | 5.9 | 0.00 | Sep 14, 2026 | The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents. | ||
| CVE-2023-45858 | Hig | 0.56 | 8.6 | 0.01 | Sep 14, 2026 | A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files. | ||
| CVE-2023-45023 | Med | 0.20 | 4.2 | 0.00 | Sep 14, 2026 | The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component. | ||
| CVE-2023-40772 | Med | 0.21 | 4.3 | 0.01 | Sep 14, 2026 | A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component. | ||
| CVE-2023-37366 | Low | 0.18 | 2.8 | 0.00 | Sep 14, 2026 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123,… | ||
| CVE-2023-37253 | Low | 0.20 | 3.1 | 0.00 | Sep 14, 2026 | An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables. | ||
| CVE-2026-90684 | Low | 0.11 | 2.8 | 0.00 | Sep 14, 2026 | A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on… | ||
| CVE-2026-90683 | Low | 0.14 | 3.3 | 0.00 | Sep 14, 2026 | A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now… | ||
| CVE-2026-90682 | Med | 0.34 | 5.3 | 0.00 | Sep 14, 2026 | A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An… | ||
| CVE-2026-90681 | Low | 0.21 | 3.3 | 0.00 | Sep 14, 2026 | A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public… | ||
| CVE-2023-37252 | Low | 0.20 | 3.1 | 0.00 | Sep 14, 2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden. | ||
| CVE-2023-34854 | Med | 0.43 | 6.6 | 0.00 | Sep 14, 2026 | HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function. | ||
| CVE-2023-32803 | Hig | 0.49 | 7.5 | 0.00 | Sep 14, 2026 | The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491. | ||
| CVE-2023-32778 | Low | 0.14 | 3.3 | 0.00 | Sep 14, 2026 | An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload. | ||
| CVE-2023-29377 | Med | 0.43 | 6.6 | 0.00 | Sep 14, 2026 | An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA… | ||
| CVE-2023-28148 | Hig | 0.47 | 7.2 | 0.00 | Sep 14, 2026 | A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520. | ||
| CVE-2023-24291 | Low | 0.19 | 2.9 | 0.00 | Sep 14, 2026 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter. | ||
| CVE-2023-24288 | Low | 0.19 | 2.9 | 0.00 | Sep 14, 2026 | An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states. | ||
| CVE-2023-24287 | Low | 0.19 | 2.9 | 0.00 | Sep 14, 2026 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command. | ||
| CVE-2023-24286 | Low | 0.19 | 2.9 | 0.00 | Sep 14, 2026 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter. | ||
| CVE-2023-24285 | Low | 0.19 | 2.9 | 0.00 | Sep 14, 2026 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed. | ||
| CVE-2023-24284 | Low | 0.19 | 2.9 | 0.00 | Sep 14, 2026 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function. | ||
| CVE-2026-90680 | Cri | 0.64 | 9.9 | 0.01 | Sep 14, 2026 | A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer… | ||
| CVE-2026-90623 | Low | 0.24 | 3.7 | 0.00 | Sep 14, 2026 | A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be… | ||
| CVE-2026-90622 | Low | 0.14 | 3.3 | 0.00 | Sep 14, 2026 | A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has… | ||
| CVE-2026-90621 | Med | 0.41 | 6.3 | 0.01 | Sep 14, 2026 | A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is… | ||
| CVE-2023-24283 | Low | 0.19 | 2.9 | 0.00 | Sep 14, 2026 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file. | ||
| CVE-2023-24035 | Low | 0.23 | 3.5 | 0.01 | Sep 14, 2026 | An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison. | ||
| CVE-2023-24034 | Low | 0.20 | 3.1 | 0.00 | Sep 14, 2026 | An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability. | ||
| CVE-2023-22632 | Low | 0.18 | 2.7 | 0.00 | Sep 14, 2026 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor. | ||
| CVE-2023-22631 | Low | 0.18 | 2.7 | 0.00 | Sep 14, 2026 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor. | ||
| CVE-2026-90620 | — | Hig | 0.47 | 7.3 | 0.00 | Sep 14, 2026 | A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can… | |
| CVE-2026-90619 | — | Hig | 0.48 | 7.3 | 0.01 | Sep 14, 2026 | A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It… | |
| CVE-2026-90618 | — | Hig | 0.40 | 7.3 | 0.02 | Sep 14, 2026 | A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection.… | |
| CVE-2026-90617 | — | Hig | 0.41 | 7.3 | 0.02 | Sep 14, 2026 | A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The… | |
| CVE-2026-38924 | Low | 0.12 | 2.9 | 0.00 | Sep 14, 2026 | In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0,… | ||
| CVE-2026-33970 | Low | 0.23 | 3.5 | 0.00 | Sep 14, 2026 | An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when… | ||
| CVE-2026-33968 | Low | 0.18 | 2.8 | 0.00 | Sep 14, 2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access. | ||
| CVE-2026-33967 | Low | 0.18 | 2.8 | 0.00 | Sep 14, 2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption. | ||
| CVE-2026-33966 | Low | 0.18 | 2.8 | 0.00 | Sep 14, 2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code. | ||
| CVE-2026-90615 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit… | ||
| CVE-2026-90614 | Med | 0.41 | 6.3 | 0.00 | Sep 14, 2026 | A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument… | ||
| CVE-2026-90613 | Low | 0.14 | 3.3 | 0.00 | Sep 14, 2026 | A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local… | ||
| CVE-2026-90612 | Low | 0.14 | 3.3 | 0.00 | Sep 14, 2026 | A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly… | ||
| CVE-2026-90611 | Low | 0.14 | 3.3 | 0.00 | Sep 14, 2026 | A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit… | ||
| CVE-2026-90610 | Low | 0.14 | 3.3 | 0.00 | Sep 14, 2026 | A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit… | ||
| CVE-2026-33964 | Med | 0.42 | 6.4 | 0.00 | Sep 14, 2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service. | ||
| CVE-2026-33963 | Hig | 0.49 | 7.5 | 0.00 | Sep 14, 2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service. |
- risk 0.44cvss —epss 0.00
Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows.
- risk 0.57cvss 8.8epss 0.00
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
- risk 0.31cvss 5.9epss 0.00
The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
- risk 0.56cvss 8.6epss 0.01
A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
- risk 0.20cvss 4.2epss 0.00
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
- risk 0.21cvss 4.3epss 0.01
A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.
- risk 0.18cvss 2.8epss 0.00
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123,…
- risk 0.20cvss 3.1epss 0.00
An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.
- risk 0.11cvss 2.8epss 0.00
A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on…
- risk 0.14cvss 3.3epss 0.00
A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now…
- risk 0.34cvss 5.3epss 0.00
A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An…
- risk 0.21cvss 3.3epss 0.00
A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public…
- risk 0.20cvss 3.1epss 0.00
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
- risk 0.43cvss 6.6epss 0.00
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
- risk 0.49cvss 7.5epss 0.00
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
- risk 0.14cvss 3.3epss 0.00
An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
- risk 0.43cvss 6.6epss 0.00
An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA…
- risk 0.47cvss 7.2epss 0.00
A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
- risk 0.19cvss 2.9epss 0.00
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.
- risk 0.19cvss 2.9epss 0.00
An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
- risk 0.19cvss 2.9epss 0.00
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.
- risk 0.19cvss 2.9epss 0.00
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.
- risk 0.19cvss 2.9epss 0.00
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.
- risk 0.19cvss 2.9epss 0.00
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
- risk 0.64cvss 9.9epss 0.01
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer…
- risk 0.24cvss 3.7epss 0.00
A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be…
- risk 0.14cvss 3.3epss 0.00
A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is…
- risk 0.19cvss 2.9epss 0.00
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.
- risk 0.23cvss 3.5epss 0.01
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.
- risk 0.20cvss 3.1epss 0.00
An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.
- risk 0.18cvss 2.7epss 0.00
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
- risk 0.18cvss 2.7epss 0.00
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can…
- risk 0.48cvss 7.3epss 0.01
A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It…
- risk 0.40cvss 7.3epss 0.02
A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection.…
- risk 0.41cvss 7.3epss 0.02
A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The…
- risk 0.12cvss 2.9epss 0.00
In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0,…
- risk 0.23cvss 3.5epss 0.00
An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when…
- risk 0.18cvss 2.8epss 0.00
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.
- risk 0.18cvss 2.8epss 0.00
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.
- risk 0.18cvss 2.8epss 0.00
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.
- risk 0.28cvss 4.3epss 0.00
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit…
- risk 0.41cvss 6.3epss 0.00
A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument…
- risk 0.14cvss 3.3epss 0.00
A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local…
- risk 0.14cvss 3.3epss 0.00
A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly…
- risk 0.14cvss 3.3epss 0.00
A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit…
- risk 0.14cvss 3.3epss 0.00
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit…
- risk 0.42cvss 6.4epss 0.00
An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.