Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-35856: GitHub - MikeIsAStar/Mario-Kart-Wii-Remote-Code-Execution: Injects arbitrary code into a client's game.

A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet.

CVE
#web#mac#git#rce#buffer_overflow
CVE-2023-34657: EyouCMS v1.6.2 has stored xss · Issue #43 · weng-xianhu/eyoucms

A stored cross-site scripting (XSS) vulnerability in Eyoucms v1.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the web_recordnum parameter.

CVE-2023-35855: GitHub - MikeIsAStar/Counter-Strike-Remote-Code-Execution: Injects arbitrary code into a client's game.

A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.

CVE-2023-35848: Various fixes on size calculation by danielinux · Pull Request #15 · virtualsquare/picotcp

VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member.

CVE-2023-35847: TCP: Fixed MSS size calculation. Set MSS lower bound. · virtualsquare/picotcp@eaf1660

VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).

CVE-2023-35846: [ipfilter] Check transport layer length in frame before filtering ports · virtualsquare/picotcp@d561990

VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not check the transport layer length in a frame before performing port filtering.

CVE-2023-35849: More checks for correct header sizes · virtualsquare/picotcp@4b9a167

VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not properly check whether header sizes would result in accessing data outside of a packet.

CVE-2023-35844: Comparing 0.510.2...0.510.3 · lightdash/lightdash

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

CVE-2023-35840: [VD:LocalFileSystem] Security fixes, directory traversal vulnerability · Studio-42/elFinder@bb9aaa7

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

CVE-2023-35839: Comparing v2.3.2...v2.3.3 · noear/solon

Solon before 2.3.3 allows Deserialization of Untrusted Data.