CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 20, 2025

IBM Security Verify Access Password Change Vulnerability for Expired Users

A vulnerability exists in IBM Security Verify Access versions 10.0.0 to 10.0.8, as well as in IBM Security Verify Access Docker versions 10.0.0 to 10.0.8. This vulnerability could allow an unverified user to change the password of an expired user without knowing the previous password.

4.0
Jan 20, 2025

WriteFreely MySQL Database Credential Exposure Vulnerability

A vulnerability in WriteFreely versions through 0.15.1 allows local users to access MySQL database credentials stored in plaintext within a world-readable config.ini file. This issue arises when WriteFreely is set up to use a MySQL database, following the standard installation instructions. The vulnerability is present on any Linux-based platform, and potentially others, affecting instances on shared hosting environments.

2.6
Jan 20, 2025

Linux Kernel io_uring Use-After-Free Vulnerability in Eventfd Handling

A use-after-free vulnerability has been identified in the Linux kernel's io_uring implementation, specifically in how eventfd signals are managed. The issue arises because the function io_eventfd_do_signal() frees a reference-counted object immediately when its reference count drops to zero, without waiting for the necessary RCU grace period. This behavior can lead to a race condition, allowing a user-space thread to access a freed object, potentially causing memory corruption or other unintended consequences.

3.3
Jan 20, 2025

OpenSSL Timing Side-Channel Vulnerability in ECDSA Signature Computation

A timing side-channel vulnerability has been identified in the ECDSA signature computation of OpenSSL. This issue allows for the potential recovery of private keys. The vulnerability is present in OpenSSL versions 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1, and 1.0.2. The timing leak occurs when the top word of the inverted ECDSA nonce value is zero, which can happen with significant probability on certain elliptic curves, particularly the NIST P-521 curve. To exploit this vulnerability, an attacker must have local access to the signing application or a very fast, low-latency network connection.

6.5
Jan 20, 2025

CP Plus Router Cookie Flag Mismanagement Vulnerability Allowing Session Hijacking

A vulnerability in the CP Plus CP-XR-DE21-S Router, specifically in firmware version DE21_S_india_hx806_1.057.043_0023, has been identified. This issue arises from the insecure handling of cookie flags in the router's web interface, which could enable a remote attacker to intercept data during an HTTP session. Successful exploitation may lead to the acquisition of sensitive information and compromise the affected system.

2.0
Jan 20, 2025

Linux Kernel Netfilter nf_tables Garbage Collection Vulnerability

A vulnerability in the Linux kernel's netfilter component, specifically within the nf_tables backend, has been addressed. This issue involved the garbage collection (GC) process, where elements were improperly managed, leading to potential visibility during lookups. The vulnerability arose because the asynchronous GC could enqueue transaction work that might be aborted and retried, causing inconsistencies. Additionally, certain backend types did not properly synchronize GC operations, leaving elements in a state that could interfere with normal processing.

5.7
Jan 20, 2025

TECNO Carlcare App Information Leakage Vulnerability

A vulnerability has been identified in the TECNO Carlcare mobile application, version 6.2.8.1, due to improper permission settings. This vulnerability may lead to a risk of information leakage.

4.1
Jan 20, 2025

aEnrich Technology a+HRD Insecure Deserialization Vulnerability Leading to Arbitrary Code Execution

An insecure deserialization vulnerability has been identified in a+HRD by aEnrich Technology, affecting versions through 7.5. This vulnerability allows remote attackers with database modification privileges and standard system privileges to execute arbitrary code.

1.1
Jan 20, 2025

aEnrich Technology a+HRD SQL Injection Vulnerability

A SQL injection vulnerability has been identified in a+HRD by aEnrich Technology, affecting versions through 7.5. This vulnerability allows unauthenticated remote attackers to inject arbitrary SQL commands, potentially leading to unauthorized reading, modification, or deletion of database contents.

2.6
Jan 20, 2025

aEnrich Technology a+HRD Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in a+HRD versions 7.5 and earlier, developed by aEnrich Technology. This vulnerability allows unauthenticated remote attackers to probe internal networks, potentially leading to unauthorized access or information disclosure.

1.5
Jan 20, 2025

itsourcecode Farm Management System Code Injection Vulnerability in add-pig.php

A critical code injection vulnerability has been identified in the itsourcecode Farm Management System, specifically in version 1.0. The issue resides in the add-pig.php file, where the pigphoto parameter allows for unrestricted file uploads. This vulnerability arises from inadequate validation and sanitization of uploaded files, enabling attackers to upload malicious code that could be executed on the server.

3.2
Jan 20, 2025

CampCodes School Management Software Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in CampCodes School Management Software version 1.0. The issue resides in the chat history component, specifically within the '/chat/group/send' file. The vulnerability is triggered by manipulating the 'message' argument, allowing for the injection of malicious scripts. This issue can be exploited remotely, and there is a potential for account takeover, particularly targeting admin users.

2.9
Jan 20, 2025

Shiprocket OpenCart Module REST API Access Bypass Vulnerability

An access bypass vulnerability has been identified in the Shiprocket OpenCart Module version 3, specifically within the REST API component. The issue arises in the file 'index.php' when the 'route=extension/module/rest_api&action=getOrders' endpoint is accessed. The vulnerability allows for incorrect authorization by manipulating the 'contentHash' argument, enabling unauthorized access to Personally Identifiable Information (PII) and other sensitive data stored in the site's database. Additionally, this flaw could be exploited to make unauthorized changes to the database.

3.9
Jan 20, 2025

Shiprocket OpenCart Module SQL Injection Vulnerability

A critical SQL injection vulnerability has been identified in the Shiprocket module for OpenCart, specifically in versions 3 and 4. The issue arises in the REST API module's endpoint, where the 'x-username' header can be manipulated to execute arbitrary SQL commands. This vulnerability allows remote attackers to access and exfiltrate sensitive database information, including admin credentials and personally identifiable information.

3.9
Jan 20, 2025

OBS Studio Untrusted Search Path Vulnerability Allowing DLL Injection

A vulnerability exists in OBS Studio versions up to 30.0.2 on Windows, related to how the application loads dynamic link library (DLL) files. The issue arises from an untrusted search path that can be exploited to inject malicious code into DLLs, potentially leading to remote code execution. This vulnerability requires local access to the affected system.

2.6
Jan 20, 2025

aEnrich Technology a+HRD Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in a+HRD by aEnrich Technology, affecting versions through 7.5. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in the user's browser, potentially through phishing attacks.

1.4
Jan 20, 2025

Facile Sistemas Cloud Apps Password Reset Handler Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Facile Sistemas Cloud Apps versions prior to 20250107. The issue arises in an unknown function within the Password Reset Handler component, specifically in the file '/account/forgotpassword'. The vulnerability is triggered by manipulating the 'reterros' argument, allowing remote attackers to inject malicious scripts. This exploit has been publicly disclosed.

1.6
Jan 20, 2025

Mobotix M15 Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability has been identified in the Mobotix M15 camera running firmware version 4.3.4.83. The issue arises from the file '/control/player' when certain parameters are manipulated, specifically 'p_qual'. This vulnerability can be exploited remotely.

2.0
Jan 19, 2025

Union Bank of India Vyom Rooting Detection Protection Mechanism Failure Vulnerability

A vulnerability in Union Bank of India Vyom version 8.0.34 for Android has been identified, related to the rooting detection component. This vulnerability leads to a failure in the application's protection mechanisms, potentially allowing for unauthorized modifications or access. The issue requires local exploitation, and while the complexity of the attack is high, the vulnerability has been disclosed publicly and may be actively exploited.

0.9
Jan 19, 2025

IBM Sterling Secure Proxy Command Injection Vulnerability in Privileged User Context

A command injection vulnerability has been identified in IBM Sterling Secure Proxy versions 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0. This vulnerability could allow a privileged user to inject commands into the underlying operating system, arising from improper validation of certain input types.

2.6
Jan 19, 2025

IBM TXSeries for Multiplatforms Denial-of-Service Vulnerability via Persistent Connections

A denial-of-service vulnerability has been identified in IBM TXSeries for Multiplatforms version 10.1. This issue could allow a remote attacker to cause a denial of service by exploiting persistent connections, due to improper resource allocation.

3.0
Jan 19, 2025

IBM TXSeries for Multiplatforms Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in IBM TXSeries for Multiplatforms version 10.1. This issue arises from improper enforcement of timeouts on individual read operations, allowing remote attackers to conduct slowloris-type attacks that disrupt service.

3.0
Jan 19, 2025

IBM Sterling Secure Proxy Unauthorized Information Retrieval or Alteration Vulnerability

A vulnerability in IBM Sterling Secure Proxy versions 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could enable an unauthorized attacker to access or modify sensitive information. This issue arises from improper permission assignments.

3.4
Jan 19, 2025

Linux Kernel Device-Mapper Array Double Free Vulnerability

A vulnerability in the Linux kernel's device-mapper array implementation can lead to a double free error. This issue arises when the block manager's read lock function fails, causing the kernel to release a faulty block while leaving an invalid pointer. Subsequent operations on this pointer can result in undefined behavior. The problem is exacerbated in the dm_array_cursor, which incorrectly caches the invalid pointer, leading to a double release when the cursor's end function is called. This vulnerability has been addressed by modifying the error handling to reset the cached pointer to null, preventing the invalid pointer from being reused.

5.6
Jan 19, 2025

Linux Kernel Netfs Memory Management Vulnerability in Buffered Reads

A vulnerability in the Linux kernel's netfs component has been addressed, specifically related to memory management during buffered read operations. The issue arose in the netfs_read_to_pagecache() function, which failed to properly handle errors from the ->prepare_read() method and the netfs_prepare_read_iterator(). When an error occurred, the function needed to decrement the ->nr_outstanding counter, cancel the subrequest, and exit the issuing loop. However, this error handling was only implemented for two of the four relevant cases. The vulnerability has been fixed by consolidating the error handling into a common location, allowing it to be applied consistently across all four cases, rather than using a wrapper around netfs_prepare_read_iterator() as initially suggested.

5.3
Jan 19, 2025

Linux Kernel NFS NULL Pointer Dereference Vulnerability in Request Initialization

A vulnerability in the Linux kernel's NFS implementation could lead to a NULL pointer dereference. This issue arises when netfslib attempts to copy data that has just been read for NFS. It creates a new write request and initializes it using nfs_netfs_init_request(), but without a valid file pointer. This omission causes nfs_file_open_context() to encounter a NULL pointer dereference. Although the NFS context is not needed for writing to the cache, the absence of a file pointer leads to a crash. The vulnerability has been addressed by modifying the request initialization function to return early when no file pointer is provided, while also issuing a warning if the request was intended for a purpose other than copying to cache. Additionally, the request cleanup function has been corrected to avoid attempting to free a NULL context pointer.

5.7
Jan 19, 2025

Linux Kernel Mediatek DRM Private Pointer Use-After-Free Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel's handling of Mediatek Direct Rendering Manager (DRM) bindings. The issue arises because the pointer to the private DRM data is not set to NULL when an error occurs during the binding process. This oversight leads to a memory access violation, as the shutdown procedure attempts to read from a memory location that has already been freed, causing a kernel memory corruption issue.

5.3
Jan 19, 2025

Linux Kernel ksmbd Missing Return Value Check Vulnerability

A vulnerability in the Linux kernel's ksmbd component was introduced by a missing return value check in the smb2_send_interim_resp() function. If the ksmbd_alloc_work_struct() function fails to allocate a node, it returns a NULL pointer to the in_work pointer. This oversight can lead to an illegal memory write of in_work->response_buf when allocate_interim_rsp_buf() tries to perform a memory allocation on it. The vulnerability has been addressed by adding a check for the return value of ksmbd_alloc_work_struct(), ensuring that the function exits immediately upon allocation failure, thus preventing the illegal memory access.

5.7
Jan 19, 2025

Linux Kernel File Handle Encoding Assertion Relaxation Vulnerability

A vulnerability in the Linux kernel related to the encoding of file handles has been addressed. The issue arose because certain users of the 'exportfs_encode_fh()' function, including 'nfsd' and the 'name_to_handle_at(2)' syscall, were not properly handling failures in file handle encoding. This oversight led to incorrect WARN_ON() assertions when encoding failed. The vulnerability could be triggered with overlayfs, inotify, and drop_caches, and was also present in kernels prior to 6.6.

5.6
Jan 19, 2025

Linux Kernel Btrfs Compression Vulnerability on S390 Hardware Acceleration

A vulnerability in the Linux kernel's Btrfs file system compression routine for S390 hardware has been identified. The issue arises because the input data length to the zlib compression function can vary, leading to a situation where the read bytes may exceed the actual input range. This discrepancy triggers an assertion failure in the Btrfs compression function, causing a kernel panic. The vulnerability has been resolved by correcting the calculation of the input length for the S390 zlib hardware compression path.

5.6
Jan 19, 2025

Linux Kernel Granularity Check Vulnerability in AMD Display Component

A vulnerability in the Linux kernel's AMD display component was addressed by adding a granularity check in certain helper functions. This vulnerability could lead to an assertion failure and a divide-by-zero error. The issue arose because the wrapper functions for bandwidth ceiling and flooring calculations did not verify that the granularity was non-zero, potentially causing a runtime error.

5.7
Jan 19, 2025

Linux Kernel AMD GPU Buddy Allocator Lock Vulnerability

A race condition issue has been identified in the Linux kernel's AMD GPU driver, specifically within the buddy allocator's trim function. This vulnerability can lead to a system hang and general protection fault, likely caused by a non-canonical address. The issue arises when YouTube videos and Steam games are run simultaneously on a multi-display configuration. The lack of proper locking when accessing the buddy trim function creates a vulnerability that can be exploited under these conditions.

5.5
Jan 19, 2025

Linux Kernel AMD Graphics Driver DMA Fence Warning Vulnerability

A vulnerability in the Linux kernel's AMD graphics driver has been addressed. The issue arose in the kernel's Direct Rendering Manager (DRM) and AMD Kernel Fusion Driver (AMDKFD) components. When a KFD process was closed immediately after being opened, it triggered a warning because the eviction fence was not properly initialized. This vulnerability could lead to a warning being generated in the system logs, indicating a potential issue with how DMA fences were managed for KFD processes.

5.2
Jan 19, 2025

Linux Kernel AMD Graphics Division Zero Division Vulnerability in Plane Scaling Calculations

A vulnerability in the Linux kernel's AMD graphics driver has been fixed, addressing a division-by-zero error in the display plane scaling calculations. The issue arose because the 'dm_get_plane_scale' function did not properly account for cases where the destination size was zero, leading to a kernel oops error. This vulnerability was introduced with the cursor overlay mode, which uses this function to evaluate cursor mode changes before verifying the plane state.

5.6
Jan 19, 2025

Linux Kernel AMD Display Page Fault Vulnerability

A vulnerability in the Linux kernel's AMD display driver has been addressed, which caused a page fault due to a mismatch in the maximum surface definition. The driver used two different values to define the maximum number of surfaces, leading to inconsistencies. This issue particularly affected users of the Cosmic distribution on AMD hardware that supports two overlay planes, following the introduction of cursor overlay mode. The vulnerability was characterized by a supervisor read access page fault in kernel mode, indicating a failure to properly manage memory access rights.

6.1
Jan 19, 2025

Linux Kernel Cpumask Handling Vulnerability in Topology Printing

A vulnerability in the Linux kernel's handling of CPU masks during topology printing has been identified. This issue arises because the core_cpumask can be altered by CPU hotplug events, leading to a mismatch in the expected and actual lengths of formatted strings when using the kvasprintf function. The vulnerability was discovered during fuzz testing, which revealed a warning about inconsistent return values from a vsnprintf test. The warning indicates that the core_cpumask was modified while it was being printed, causing the discrepancy.

5.1
Jan 19, 2025

Linux Kernel GPIO IRQ Handling Vulnerability Leading to Kernel Panic

A vulnerability in the Linux kernel's handling of GPIO interrupts has been addressed. The issue caused a kernel panic due to improper management of interrupt requests while accessing GPIO values. This vulnerability was resolved by replacing 'generic_handle_irq' with 'handle_nested_irq', ensuring a more reliable handling of interrupts and preventing the kernel panic.

5.3
Jan 19, 2025

Linux Kernel NULL Pointer Dereference Vulnerability in USB Type-C TCPCI Handling

A NULL pointer dereference vulnerability has been identified in the Linux kernel's USB Type-C TCPCI (Type-C Port Controller Interface) handling. This issue arises in the interrupt handler for TCPCI ports that share an interrupt request (IRQ). When the second port's interrupt handler is triggered before the first port has fully registered, it can attempt to access a NULL pointer, leading to a kernel crash. The vulnerability has been observed in the NXP i.MX93 11X11 EVK board.

5.6
Jan 19, 2025

Linux Kernel FunctionFS Bind Race Condition Vulnerability Leading to Kernel Panic

A race condition vulnerability has been identified in the Linux kernel's USB gadget functionality, specifically within the functionfs_bind process. This vulnerability can cause a kernel panic when the 'panic_on_warn' option is enabled. The issue arises from the improper use of WARN_ON in functionfs_bind, creating a race condition between ADB (Android Debug Bridge) operations and UDC (USB Device Controller) writes via configfs. The vulnerability has been addressed by removing the unnecessary WARN_ON, preventing the kernel panic scenario.

5.5
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in IIO Pressure ZPA2326

A vulnerability has been identified in the Linux kernel's IIO pressure driver for the ZPA2326 sensor. The issue involves an information leak from a triggered buffer to user space. The local 'sample' structure, which is used to transfer data, contains an uninitialized gap between the temperature and timestamp fields. This gap can lead to the exposure of uninitialized data to user space. The vulnerability has been addressed by initializing the structure to zero before use.

5.3
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in IIO Dummy Buffer

A vulnerability in the Linux kernel's IIO (Industrial I/O) subsystem has been addressed. The issue involved the 'data' array in the 'iio_simply_dummy_buffer' component, which was allocated using kmalloc() to transfer data from a triggered buffer to user space. However, the array did not initialize values for inactive channels, leading to the potential leakage of uninitialized data to userspace. This vulnerability has been fixed by changing the memory allocation to use kzalloc(), which ensures that the data is properly initialized before being sent to user space.

5.7
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in IIO Light VCNL4035 Driver

A vulnerability has been identified in the Linux kernel's IIO light VCNL4035 driver, where the local 'buffer' array used to transfer data to userspace from a triggered buffer does not initialize its single data element, a u16 aligned to 8 bytes. This oversight leaves at least 4 bytes uninitialized, even after an integer value is read using regmap_read(). The vulnerability could lead to an information leak by sending uninitialized data to userspace. The issue has been addressed by initializing the array to zero before use.

5.7
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in IIO Light BH1745 Driver

A vulnerability in the Linux kernel's IIO light BH1745 driver has been addressed, which involved an information leak from the triggered buffer to user space. The issue arose because the 'scan' local structure did not initialize values for inactive channels, leading to the transmission of uninitialized data. The vulnerability has been fixed by ensuring the structure is zeroed out before use, preventing the leakage of undefined information to users.

5.3
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in IIO KMX61 Driver

A vulnerability in the Linux kernel's IIO (Industrial I/O) subsystem, specifically within the KMX61 inertial measurement unit (IMU) driver, has been addressed. The issue involved an information leak through the triggered buffer mechanism. The local 'buffer' array, used to transfer data to user space, failed to initialize values for inactive channels, leading to the potential exposure of uninitialized data. This vulnerability has been resolved by ensuring the array is properly zeroed before use, preventing the leakage of uninitialized information to userspace.

5.7
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in Rockchip SAR ADC IIO Driver

A vulnerability in the Linux kernel's IIO ADC Rockchip SAR ADC driver allows for an information leak from a triggered buffer to userspace. The issue arises because the driver does not initialize values for inactive channels, leading to the transmission of uninitialized data. This vulnerability has been addressed by modifying the driver to zero-initialize the data structure before use, ensuring that no stray data is sent to userspace.

5.7
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in IIO ADC TI-ADS8688

A vulnerability in the Linux kernel's IIO ADC TI-ADS8688 driver allows for an information leak through the triggered buffer. The issue arises because the local 'buffer' array, which transmits data to user space, does not initialize values for inactive channels. It only uses active channels to assign new values, leading to the potential exposure of uninitialized data. This vulnerability has been addressed by modifying the driver to zero-initialize the buffer array before use, ensuring that no uninitialized information is sent to userspace.

5.7
Jan 19, 2025

Linux Kernel Information Leak Vulnerability in IIO ADC TI-ADS1119

A vulnerability in the Linux kernel's IIO ADC TI-ADS1119 driver has been addressed, which involved an information leak from the triggered buffer to user space. The issue arose because the 'scan' local structure, used to transfer data, contained an uninitialized gap between the sample and the timestamp. This gap could inadvertently expose uninitialized data to user space. The vulnerability has been resolved by initializing the structure to zero before use.

5.3
Jan 19, 2025

Linux Kernel Input Device Management Vulnerability in AT91 ADC Driver

A vulnerability exists in the Linux kernel's AT91 ADC driver within the input device management process. The issue arises in the 'at91_ts_register()' function, where 'input_free_device()' is called on a variable that has not yet been properly initialized. This flaw can lead to improper handling of input devices, potentially causing memory management issues.

5.7
Jan 19, 2025

Linux Kernel OverlayFS Inode Handling Vulnerability in inotify Integration

A vulnerability in the Linux kernel's OverlayFS implementation can be triggered by userspace interactions with inotify. When an OverlayFS inode's dentry aliases are discarded, the inotify_show_fdinfo() function can encounter a WARN_ON() assertion failure. This issue arises because the function fails to encode the file handle for the OverlayFS inode, which is critical for proper event reporting. The problem stems from the ovl_encode_fh() function's reliance on finding an alias for the inode, a step that can be deferred to avoid failures in common scenarios, such as with FAN_DELETE_SELF events.

6.1
Jan 19, 2025

Linux Kernel Shift-Out-of-Bounds Vulnerability in Flow Classifier

A vulnerability in the Linux kernel's network scheduling component, specifically within the flow classification code, has been identified. The issue arises because the TCA_FLOW_RSHIFT attribute was not properly validated, allowing for undefined behavior when a 32-bit integer is right-shifted by large values. This flaw was detected by the Undefined Behavior Sanitizer, which reported a shift-out-of-bounds error. The vulnerability is present in version 6.13.0-rc3 and could be exploited during the IPv6 address resolution process, potentially leading to incorrect packet handling or transmission.

5.6