Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in /nav_bar_action.php of Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat box.
Published Jul 27, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in getprop_builtin_foreign() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins.
Published Jul 22, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a use-after-free in expr_traverse_nodes_post() in libyasm/expr.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr__copy_except() in libyasm/expr.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmac_params() in modules/preprocs/nasm/nasm-pp.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in nasm_parser_directive() in modules/parsers/nasm/nasm-parse.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_next() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_part_get_by_offset() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at 0x7fffe9049390.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is Integer overflow in gc_compact_strings() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_string_char_code_at() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in find_cc() in modules/preprocs/nasm/nasm-pp.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_print() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_commit() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in if_condition() in modules/preprocs/nasm/nasm-pp.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in hash() in modules/preprocs/nasm/nasm-pp.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a use-after-free in yasm_intnum_destroy() in libyasm/intnum.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in json_printf() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in exec_expr() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr_get_intnum() in libyasm/expr.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.
Published Jul 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP files from the internal server network by inserting an internal address.
Published Jul 14, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.
Published Jul 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
Published Jul 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.
Published Jul 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.
Published Jul 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SVG image.
Published Jul 14, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.
Published Jul 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to write files to arbitrary directories via relative paths in ZIP archives.
Published Jul 14, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive).
Published Jul 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
Published Jul 9, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.
Published Jul 7, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.
Published Jul 26, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
Published Jul 12, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including version 3.57.5 allows remote unauthenticated attackers to execute system commands as root via a simple HTTP request.
Published Jul 22, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
Published Jul 19, 2021 · Updated Aug 3, 2024
High · CVSS 8.1
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. The issue is patched in `stable` version 2.7.6, `beta` version 2.8.0.beta3, and `tests-passed` version 2.8.0.beta3. As a workaround, ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.
Published Jul 15, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that is accessible in the context of the user executing software.
Published Jul 9, 2021 · Updated Aug 3, 2024
Medium · CVSS 5.9
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in mod_auth_openidc uses a static IV and AAD. It is important to fix because this creates a static nonce and since aes-gcm is a stream cipher, this can lead to known cryptographic issues, since the same key is being reused. From 2.4.9 onwards this has been patched to use dynamic values through usage of cjose AES encryption routines.
Published Jul 26, 2021 · Updated Aug 3, 2024
High · CVSS 7.7
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.
Published Jul 21, 2021 · Updated Aug 3, 2024