Low · CVSS 3.5
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.5.1 is able to address this issue. The name of the patch is 3f39f2d68d11895929c04f7b49b97a734ae7cd1f. It is recommended to upgrade the affected component. VDB-216862 is the identifier assigned to this vulnerability.
Published Dec 27, 2022 · Updated Aug 5, 2024
Low · CVSS 3.5
A vulnerability, which was classified as problematic, has been found in Hide Files on GitHub up to 2.x. This issue affects the function addEventListener of the file extension/options.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is 9de0c57df81db1178e0e79431d462f6d9842742e. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216767.
Published Dec 25, 2022 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the pnet crate before 0.27.2 for Rust. There is a segmentation fault (upon attempted dereference of an uninitialized descriptor) because of an erroneous IcmpTransportChannelIterator compiler optimization.
Published Dec 26, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the libpulse-binding crate before 2.6.0 for Rust. It mishandles a panic that crosses a Foreign Function Interface (FFI) boundary.
Published Dec 26, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the failure crate through 2019-11-13 for Rust. Type confusion can occur when __private_get_type_id__ is overridden.
Published Dec 31, 2020 · Updated Aug 5, 2024
Medium · CVSS 6.3
A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gvdb-builder.c. The manipulation leads to use after free. It is possible to initiate the attack remotely. The name of the patch is d83587b2a364eb9a9a53be7e6a708074e252de14. It is recommended to apply a patch to fix this issue. The identifier VDB-216789 was assigned to this vulnerability.
Published Dec 26, 2022 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can cause a panic.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itself and thus has degenerate security properties.
Published Dec 31, 2020 · Updated Aug 5, 2024
Low · CVSS 3.1
A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file src/muon/handler.clj. The manipulation leads to insufficiently random values. The attack can be launched remotely. Upgrading to version 0.2.0-indev is able to address this issue. The name of the patch is c09ed972c020f759110c707b06ca2644f0bacd7f. It is recommended to upgrade the affected component. The identifier VDB-216877 was assigned to this vulnerability.
Published Dec 27, 2022 · Updated Aug 5, 2024
Unknown · CVSS Not scored
NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.
Published Dec 31, 2020 · Updated Aug 5, 2024
Medium · CVSS 5.3
A vulnerability classified as problematic was found in pacparser up to 1.3.x. Affected by this vulnerability is the function pacparser_find_proxy of the file src/pacparser.c. The manipulation of the argument url leads to buffer overflow. Attacking locally is a requirement. Upgrading to version 1.4.0 is able to address this issue. The name of the patch is 853e8f45607cb07b877ffd270c63dbcdd5201ad9. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-215443.
Published Dec 13, 2022 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the chacha20 crate before 0.2.3 for Rust. A ChaCha20 counter overflow makes it easier for attackers to determine plaintext.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-channel attack; consequently, attackers can obtain sensitive information.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong answer.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the flatbuffers crate before 0.6.1 for Rust. Arbitrary bytes can be reinterpreted as a bool, defeating soundness.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Published Dec 31, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gf_isom_box_dump_ex() in isomedia/box_funcs.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a memory leak in dinf_New() in isomedia/box_code_base.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only virtual address space, which allows local users to gain privileges by overwriting a return address that was found on the kernel stack.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trak_Read() in isomedia/box_code_base.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_box_del() in isomedia/box_funcs.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function senc_Parse() in isomedia/box_code_drm.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEMU process in the host system via a special SCSI_IOCTL_SEND_COMMAND. It hits an assertion that implies that the size of successful DMA transfers there must be a multiple of 512 (the size of a sector). NOTE: a member of the QEMU security team disputes the significance of this issue because a "privileged guest user has many ways to cause similar DoS effect, without triggering this assert.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block that was not allocated, leading to an invalid free and segmentation fault.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_dump() in isomedia/box_dump.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to NULL pointer dereference while running strlen() on a NULL pointer.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling, leading to a heap-based buffer over-read in the "normalize line endings" feature.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1_parse_tile_group() in media_tools/av_parsers.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.
Published Dec 28, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculation.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Published Dec 27, 2019 · Updated Aug 5, 2024