Search Results (94514 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-39908 1 Yubico 1 Yubihsm 2 Sdk 2024-11-21 7.5 High
The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.
CVE-2023-39902 2 Nxp, U Boot Secondary Program Loader\/spl\/ 6 I.mx 8m, I.mx 8m Mini, I.mx 8m Nano and 3 more 2024-11-21 7 High
A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing unauthenticated software to execute on the target, leading to privilege escalation. This affects i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus.
CVE-2023-39829 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.
CVE-2023-39828 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.
CVE-2023-39827 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.
CVE-2023-39748 2 Tp-link, Tp Link 3 Tl-wr1041n V2, Tl-wr1041n V2 Firmware, Tl-wr1041n 2024-11-21 7.5 High
An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CVE-2023-39745 1 Tp-link 9 Tl-wr841n, Tl-wr841n V8, Tl-wr841n V8 Firmware and 6 more 2024-11-21 7.5 High
TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CVE-2023-39740 1 Linecorp 1 Onigiriya-musubee 2024-11-21 8.2 High
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39739 1 Linecorp 1 Regina Sweets\&bakery 2024-11-21 8.2 High
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39737 1 Linecorp 1 Matsuya 2024-11-21 8.2 High
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39736 1 Linecorp 1 Fukunaga Memberscard 2024-11-21 8.2 High
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39735 1 Linecorp 1 Uomasa Saiji New 2024-11-21 8.2 High
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39734 1 Linecorp 1 Trackdiner10\/10 Mc 2024-11-21 8.2 High
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39733 1 Linecorp 1 Tonton-tei 2024-11-21 8.2 High
The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39732 1 Linecorp 1 Tokueimaru Waiting 2024-11-21 8.2 High
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39685 1 Hjson 1 Hjson 2024-11-21 7.5 High
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.
CVE-2023-39680 1 Sollace 1 Unicopia 2024-11-21 7.5 High
Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.
CVE-2023-39669 2 D-link, Dlink 3 Dir-880l, Dir-880l A1, Dir-880l A1 Firmware 2024-11-21 7.5 High
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.
CVE-2023-39663 1 Mathjax 1 Mathjax 2024-11-21 7.5 High
Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.
CVE-2023-39620 2 Buffalo, Buffalo America Inc 3 Terastation Nas 5410r, Terastation Nas 5410r Firmware, Terastation Nas Ts5410r 2024-11-21 7.5 High
An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest account function.