CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
H3C N12 V100R005 Buffer Overflow Vulnerability in AP Configuration Function
A buffer overflow vulnerability has been identified in the H3C N12 router, specifically in the V100R005 version. This vulnerability arises from inadequate length verification in the access point (AP) configuration function. Attackers exploiting this issue can cause the device to crash or execute arbitrary commands by sending a POST request to the '/bin/webs' endpoint.
H3C N12 V100R005 Buffer Overflow Vulnerability in MAC Address Update Function
A buffer overflow vulnerability has been identified in the H3C N12 V100R005 router model. This vulnerability arises from the MAC address update function's failure to properly verify the length of incoming data. Attackers who exploit this vulnerability can cause the device to crash or execute arbitrary commands by sending a specially crafted POST request to the device's web interface.
H3C N12 V100R005 Buffer Overflow Vulnerability in 2.4G Wireless Network Processing
A buffer overflow vulnerability has been identified in the H3C N12 router, specifically in the V100R005 version. This vulnerability arises from inadequate length verification in the 2.4G wireless network processing function. Attackers who exploit this vulnerability can cause the device to crash or execute arbitrary commands by sending a POST request to the '/bin/webs' endpoint.
GestioIP Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in GestioIP version 3.5.7. The issue arises in the 'ip_mod_dns_key_form.cgi' request, where an attacker can inject malicious code into the 'TSIG Key' field. This injected code is saved in the database and executed when the data is viewed, potentially leading to data exfiltration and allowing cross-site request forgery attacks.
GestioIP Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in GestioIP version 3.5.7. The issue arises in the 'ip_import_acl_csv' request, where improperly formatted file uploads can result in the content being reflected in the HTML response. This flaw allows attackers to execute malicious scripts or exfiltrate data.
GestioIP Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in GestioIP version 3.5.7. This issue allows an attacker to perform actions on behalf of an administrator by sending them a malicious link. When the admin clicks the link, the attacker's actions are executed, potentially leading to unauthorized data modification, deletion, or exfiltration.
GestioIP Cross-Site Scripting Vulnerability in IP Do Job Request
A Cross-Site Scripting (XSS) vulnerability has been identified in GestioIP version 3.5.7. The issue arises in the 'ip_do_job' request, where improper handling of user input allows for the injection of malicious scripts. This vulnerability not only facilitates XSS but also enables Cross-Site Request Forgery (CSRF) attacks and requires specific user permissions within the application for successful exploitation.
GestioIP Remote Code Execution Vulnerability
A remote code execution vulnerability exists in GestioIP version 3.5.7. The issue arises from the file upload functionality, which allows an authenticated attacker to upload a malicious file named 'perlcmd.cgi'. This file overwrites the existing 'upload.cgi' file, thereby enabling the execution of arbitrary commands on the server.
Lenovo XClarity Administrator Privilege Escalation Vulnerability via Single Sign-On
A privilege escalation vulnerability exists in Lenovo XClarity Administrator (LXCA) versions prior to 4.1. When LXCA is used as a Single Sign-On (SSO) provider for XCC instances, a valid, authenticated LXCA user could escalate permissions for a connected XCC instance.
Lenovo PC Manager, Browser, and App Store Buffer Overflow Vulnerability Allowing Local Denial-of-Service
A buffer overflow vulnerability has been identified in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store. This vulnerability could allow a local attacker to cause a system crash. Affected versions include Lenovo PC Manager versions prior to 5.1.90.12092, Lenovo Browser versions prior to 9.0.5.12181, and Lenovo App Store versions prior to 9.0.20.
Lenovo PC Manager, Browser, and App Store Potential TOCTOU Vulnerability Leading to System Crash
A potential time-of-check to time-of-use (TOCTOU) vulnerability has been identified in Lenovo PC Manager, Lenovo Browser, and the Lenovo App Store. This vulnerability could allow a local attacker to cause a system crash.
IPv6-in-IPv4 Tunneling Vulnerability Allows Traffic Spoofing and Routing via Exposed Interfaces
A vulnerability exists in the IPv6-in-IPv4 tunneling mechanism, as defined in RFC 4213, allowing an attacker to spoof and route traffic through a vulnerable host's network interface. This issue arises because the tunneling protocol lacks authentication, enabling the injection of traffic from any source. The vulnerability is present in hosts that accept unencrypted tunneling packets without verifying the sender's identity, effectively turning the host into a one-way proxy for the attacker.
IPv4-in-IPv6 and IPv6-in-IPv6 Tunneling Vulnerability Allowing Traffic Spoofing and Routing
A vulnerability exists in IPv4-in-IPv6 and IPv6-in-IPv6 tunneling protocols, as defined in RFC 2473, due to the lack of source packet validation. This flaw enables an attacker to spoof and route arbitrary traffic through a vulnerable host's network interface. The issue arises from the protocols' inherent design, which does not authenticate or encrypt traffic, leaving them open to exploitation. This vulnerability is particularly concerning because it can be used to bypass network filters and conduct anonymous attacks, similar to a previously identified vulnerability in IP-in-IP tunneling (CVE-2020-10136).
Adobe Substance 3D Designer Heap-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A heap-based buffer overflow vulnerability has been identified in Adobe Substance 3D Designer versions 14.0 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Designer Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing out-of-bounds write has been identified in Adobe Substance 3D Designer versions 14.0 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Designer Heap-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A heap-based buffer overflow vulnerability has been identified in Adobe Substance 3D Designer versions 14.0 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Designer Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing out-of-bounds write has been identified in Adobe Substance 3D Designer versions 14.0 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Animate Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing integer underflow has been identified in Adobe Animate versions 24.0.6, 23.0.9 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
TYPO3 Cross-Site Request Forgery Vulnerability in DB Check Module
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in TYPO3 versions 11.0.0 through 11.5.41. This issue arises in the backend user interface, specifically within the DB Check Module, which is part of the TYPO3 CMS low-level extensions. The vulnerability allows attackers to perform unauthorized data manipulations by exploiting state-changing actions that improperly accept HTTP GET submissions instead of the required HTTP methods. Successful exploitation necessitates that the victim has an active backend session and is tricked into clicking a malicious link that targets the backend. This can happen if the 'security.backend.enforceReferrer' feature is turned off and the 'BE/cookieSameSite' setting is configured to 'lax' or 'none'.
TYPO3 Cross-Site Request Forgery Vulnerability in Scheduler Module
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in TYPO3 versions 11.0.0 through 11.5.41, specifically within the backend user interface's deep link functionality. This issue arises because state-changing actions in the downstream 'Scheduler Module' improperly accepted submissions via HTTP GET, failing to enforce the correct HTTP method. Exploitation requires the victim to have an active backend session and to be tricked into clicking a malicious link, particularly under conditions where the 'security.backend.enforceReferrer' feature is disabled and the 'BE/cookieSameSite' configuration is set to lax or none. Successful exploitation allows attackers to trigger predefined command classes in the Scheduler Module, potentially leading to unauthorized data import or export.
TYPO3 Cross-Site Request Forgery Vulnerability in Indexed Search Module
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in TYPO3's backend user interface, specifically within the Indexed Search Module. This issue arises because deep link functionality does not properly enforce HTTP method requirements, allowing state-changing actions to be submitted via HTTP GET. Exploitation requires the victim to have an active backend session and to be tricked into clicking a malicious link, particularly under certain misconfigured settings. When successfully exploited, attackers can delete items within the Indexed Search component.
TYPO3 Form Framework Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the TYPO3 Form Framework Module, affecting versions 10.0.0 through 10.4.47, 11.0.0 through 11.5.41, 12.0.0 through 12.4.24, and 13.0.0 through 13.4.2. The vulnerability arises from the backend user interface's deep link functionality, which improperly accepts state-changing actions via HTTP GET, lacking the necessary enforcement of correct HTTP methods. Exploitation requires the victim to have an active backend session and to be tricked into clicking a malicious link, particularly under conditions where the 'security.backend.enforceReferrer' feature is disabled and the 'BE/cookieSameSite' setting is lax or absent. Successful exploitation allows attackers to manipulate or delete saved form definitions.
TYPO3 Extension Manager Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the TYPO3 backend user interface, specifically within the Extension Manager Module. This issue arises because state-changing actions in downstream components improperly accepted submissions via HTTP GET, failing to enforce the correct HTTP method. Exploitation requires the victim to have an active session in the backend and to be tricked into clicking a malicious link that targets the backend. This could happen if the user opens a harmful link, such as one sent through email, or visits a compromised website with certain misconfigurations: the 'security.backend.enforceReferrer' feature turned off, and the 'BE/cookieSameSite' setting set to 'lax' or 'none'. The vulnerability allows attackers to access and install third-party extensions from the TYPO3 Extension Repository, potentially leading to remote code execution.
TYPO3 Dashboard Module Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the TYPO3 backend user interface, specifically within the Dashboard Module. This issue arises from deep link functionality that improperly accepts state-changing actions via HTTP GET, lacking the necessary enforcement of correct HTTP methods. Exploitation requires the victim to have an active backend session and to be misled into clicking a malicious link, particularly under conditions where the 'security.backend.enforceReferrer' feature is turned off and the 'BE/cookieSameSite' setting is lax or absent.
TYPO3 Backend User Module Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the TYPO3 backend user interface, specifically within the user module of the 'beuser' extension. This issue arises because deep link functionality does not properly validate HTTP methods, allowing state-changing actions to be exploited. To successfully exploit this vulnerability, a user must have an active backend session and be tricked into clicking a malicious link. This exploitation is facilitated by certain misconfigurations, such as disabling the 'security.backend.enforceReferrer' feature and setting the 'BE/cookieSameSite' configuration to 'lax' or 'none'. Once exploited, attackers can initiate password resets for other backend users or terminate their sessions.
TYPO3 Log Module Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the TYPO3 backend user interface, specifically within the Log Module of the belog extension. This issue arises because state-changing actions in the Log Module improperly accepted HTTP GET requests without enforcing the correct HTTP method. Exploitation requires the victim to have an active backend session and to be tricked into clicking a malicious link that targets the backend. This can happen if the user opens a harmful link, such as one sent via email, or visits a compromised website while certain security settings are misconfigured. The vulnerability allows attackers to delete log entries.
TYPO3 Open Redirect and SSRF Vulnerability in URI Parsing Component
A vulnerability allowing open redirect or Server-Side Request Forgery (SSRF) has been identified in TYPO3 applications that use the 'TYPO3\CMS\Core\Http\Uri' component to parse externally provided URLs, such as those received via query parameters. This issue arises when the parsed URL's host is validated but the URL is subsequently used, potentially leading to unauthorized redirection or SSRF attacks.
TYPO3 CMS Install Tool Password Logging Vulnerability
A vulnerability in TYPO3 CMS versions 13.4.2 has been identified, where the Install Tool password was logged in plaintext. This occurred if the password hashing mechanism was incorrect. Users are recommended to update to TYPO3 version 13.4.3 LTS, which addresses this issue. No workarounds are available.
Git LFS Credential Retrieval Vulnerability via Crafted HTTP URLs
A vulnerability in Git Large File Storage (LFS) versions 0.1.0 prior to 3.6.0 allows for the retrieval of Git credentials through manipulated HTTP URLs. When Git LFS requests credentials from Git for a remote host, it inadvertently includes parts of the host's URL in the `git-credential` command without removing embedded line-ending control characters. This oversight enables attackers to insert URL-encoded control characters, such as line feed (LF) or carriage return (CR), into the URL, potentially leading to the extraction of a user's Git credentials. The issue arises because the Git credential helper cannot distinguish between legitimate line feed characters and those added by the URL encoding, causing a credential request to fail if a line feed is detected. This vulnerability is similar to a previously addressed issue in Git, indicating a common flaw in handling URL-encoded data.
QNX SDP PCX Image Codec Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the PCX image codec of QNX Software Development Platform (SDP) versions 8.0, 7.1, and 7.0. This vulnerability arises from improper input validation, which could allow an unauthenticated attacker to disrupt the process using the image codec by inducing it to parse a maliciously crafted PCX format image file.
Wikimedia Foundation MediaWiki SocialProfile Extension Information Exposure Vulnerability
A vulnerability in the Wikimedia Foundation MediaWiki SocialProfile Extension allows unauthorized users to access sensitive information. This issue arises because the Special:EditProfile page does not properly respect the visibility settings of profile fields. As a result, a user with the 'editothersprofiles' permission can view 'hidden' fields or those designated for 'friends' or 'friends of friends' when they are not in the user's friend circle. The vulnerability affects MediaWiki SocialProfile Extension versions 1.39.X prior to 1.39.11, 1.41.X prior to 1.41.3, and 1.42.X prior to 1.42.2.
Wikimedia MediaWiki GlobalBlocking Extension Sensitive Data Exposure Vulnerability
A vulnerability in the GlobalBlocking Extension of Wikimedia's MediaWiki allows unauthorized retrieval of embedded sensitive data. This issue affects the master branch of the extension. When a global block is applied to a user, the associated IP address can be exposed through the 'globalblocks' API, revealing details of the autoblock. This vulnerability was present in a beta environment but not in any production release.
Wikimedia MediaWiki RefreshSpecial Extension Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the RefreshSpecial extension for MediaWiki. This issue affects versions 1.39.X prior to 1.39.11, 1.41.X prior to 1.41.3, and 1.42.X prior to 1.42.2. The vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that could be executed in the context of the user's browser.
Gradio Path ACL Bypass Vulnerability Allowing Unauthorized File Access
A vulnerability in Gradio's Access Control List (ACL) for file paths allows for bypassing restrictions on blocked files or directories. This issue arises from the absence of case normalization in the file path validation process. On case-insensitive file systems like those used by Windows and macOS, attackers can exploit this flaw to access sensitive files that should be protected. The vulnerability could lead to unauthorized data access, exposing critical information and compromising Gradio's security model. This issue affects Gradio versions prior to 5.6.0 and has been addressed in version 5.6.0.
Umbraco.Forms Server-Side Validation Vulnerability for Character Limits in Short and Long Answer Fields
A vulnerability exists in Umbraco.Forms versions through 10.5.7 and prior to 8.13.16, allowing character limits set by editors for short and long answer fields to be validated only on the client side, with no server-side enforcement. This could lead to fields being submitted with excessive characters, potentially causing issues downstream. The vulnerability arises because the framework does not properly validate input lengths on the server, leaving room for overlong submissions that could disrupt application functionality.
Adobe Illustrator on iPad Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in Adobe Illustrator on iPad, specifically in versions 3.0.7 and earlier. This issue arises from an integer underflow vulnerability that could be exploited if a user opens a malicious file. The exploitation occurs within the context of the current user.
Adobe Illustrator for iPad Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in Adobe Illustrator on iPad, affecting versions 3.0.7 and earlier. This issue arises from an integer underflow vulnerability that could be exploited if a user opens a malicious file. The execution of arbitrary code would occur in the context of the current user.
Adobe Substance 3D Stager Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
An out-of-bounds write vulnerability has been identified in Adobe Substance 3D Stager versions through 3.0.4. This vulnerability could allow arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
An out-of-bounds write vulnerability has been identified in Adobe Substance 3D Stager versions 3.0.4 and earlier. This vulnerability could allow for arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
An out-of-bounds write vulnerability has been identified in Adobe Substance 3D Stager versions 3.0.4 and earlier. This vulnerability could allow arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Heap-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A heap-based buffer overflow vulnerability has been identified in Adobe Substance 3D Stager versions through 3.0.4. This vulnerability could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A stack-based buffer overflow vulnerability has been identified in Adobe Substance 3D Stager versions through 3.0.4. This vulnerability could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Photoshop Desktop Uncontrolled Search Path Element Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in Adobe Photoshop Desktop versions 25.12, 26.1 and earlier. This issue arises from an Uncontrolled Search Path Element vulnerability, where an attacker can manipulate the search path environment variable to direct the application to a malicious library. When the application loads this library, it can execute arbitrary code. Exploitation of this vulnerability requires user interaction, as the victim must manually run the affected application.
Adobe Photoshop Desktop Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing integer underflow has been identified in Adobe Photoshop Desktop versions 25.12, 26.1 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Invoice Ninja Authenticated Server-Side Request Forgery Vulnerability Allowing Arbitrary File Read and Network Resource Requests
A server-side request forgery (SSRF) vulnerability has been identified in Invoice Ninja versions 5.8.56 prior to 5.11.23. This vulnerability allows authenticated users to make arbitrary file read requests and access network resources on behalf of the application user.
Django Denial-of-Service Vulnerability in IPv6 Validation
A denial-of-service vulnerability has been identified in Django versions 5.1 prior to 5.1.5, 5.0 prior to 5.0.11, and 4.2 prior to 4.2.18. The issue arises from a lack of upper-bound limit enforcement in strings used for IPv6 validation, potentially leading to a denial-of-service attack. This vulnerability affects the private functions 'clean_ipv6_address' and 'is_valid_ipv6_address', as well as the 'django.forms.GenericIPAddressField' form field. However, the 'django.db.models.GenericIPAddressField' model field is not affected.
Git Credential Manager Carriage Return Handling Vulnerability Allows Credential Injection
A vulnerability exists in Git Credential Manager (GCM) due to improper handling of Carriage Return characters in URLs. This issue arises because Git and GCM interpret newlines differently, leading to a scenario where credentials for one server can be mistakenly sent to another. The vulnerability affects GCM versions through 2.6.0 and has been patched in 2.6.1. Users are advised to upgrade or, if unable to do so, to avoid cloning from untrusted URLs, especially with the recursive option.
Git Credential Handling Vulnerability Allows Credential Misleading via Control Sequences
A vulnerability in Git's credential handling can mislead users into providing sensitive information, such as passwords, for trusted Git hosting sites. This occurs when Git prompts for credentials in the terminal without using a credential helper. The vulnerability is present in Git versions 2.48.0 through 2.47.1, 2.46.2 through 2.45.2, 2.44.2, 2.43.5, 2.42.3, 2.41.2, and 2.40.3. During the credential prompt, Git prints the host name with any URL-encoded parts decoded, allowing attackers to craft URLs with ANSI escape sequences. These sequences can confuse users into sending passwords to untrusted sites under the attacker's control.
Git Credential Manager Carriage-Return Character Handling Vulnerability Allows Credential Leakage
A vulnerability in Git Credential Manager (GCM) exists due to improper handling of carriage-return characters in the Git credential protocol. GCM, a secure credential helper built on .NET, reads credentials from standard input as key-value pairs. While Git treats carriage-return characters as invalid, GCM's underlying .NET implementation considers them as newlines. This discrepancy allows attackers to craft malicious URLs that, when accessed, can leak credentials for other Git remotes. The issue is exacerbated when cloning repositories with submodules using the '--recursive' option, as submodule URLs cannot be inspected beforehand.
Rasa Remote Code Execution Vulnerability via Malicious Model Loading
A critical remote code execution vulnerability has been identified in Rasa Open Source versions prior to 3.6.21 and Rasa Pro versions prior to 3.10.12, 3.9.16, and 3.8.18. The vulnerability allows an attacker to execute arbitrary code by loading a maliciously crafted model into a Rasa instance. This issue arises when the HTTP API is enabled without proper authentication or security controls, creating an opportunity for exploitation.
