CVE Browser
StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostn…
A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, which could l…
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker coul…
A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any lo…
A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to…
polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector
A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects…
A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escala…
nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks
kernel: Heap buffer overflow in firedtv driver
openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured
krb5: NULL pointer dereference in process_tgs_req() in kdc/do_tgs_req.c via a FAST inner body that lacks server field
kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after-free
kernel: fuse: fuse_do_getattr() calls make_bad_inode() in inappropriate situations
rpm: Signature checks bypass via corrupted rpm package
SDL2: Integer overflow in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file
kernel: perf_event_parse_addr_filter memory
kernel: use-after-free in read in vt_do_kdgkb_ioctl
kernel: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow
kernel: out-of-bounds reads in pinctrl subsystem.
kernel: buffer uses out of index in ext3/4 filesystem
kernel: umask not applied on filesystem without ACL support
vim: users can execute arbitrary OS commands via scripting interfaces in the rvim restricted mode
libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes
Showing 1 to 25 CVEs · page 1 (more available)