Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-4212

?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

CVE
#vulnerability
CVE-2023-3699

An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

CVE-2023-39599: CVE/CVE-2023-39599/Readme.md at main · desencrypt/CVE

Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.

CVE-2023-39141: webui-aria2 CVE-2023-39141

webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

CVE-2023-38996: ِUTM and Firewall - Douran Group

An issue in all versions of Douran DSGate allows a local authenticated privileged attacker to execute arbitrary code via the debug command.

CVE-2023-38666: SEGV on unknown address 0x000000000028 in mp4encrypt · Issue #784 · axiomatic-systems/Bento4

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.

CVE-2023-37440

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal     structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information.

CVE-2023-38665: Invalid Bug ID

Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash).

CVE-2023-38667: Invalid Bug ID

Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service.

CVE-2023-38668: Invalid Bug ID

Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).