The GitHub Security Lab team has identified several potential security vulnerabilities in NTOP nDPI, including RCE and DoS.
An OOB write in AOSP allows an attacker within NFC range to obtain remote code execution on android device's NFC daemon.
An OOB write in AOSP allows an attacker within NFC range to obtain remote code execution on android device's NFC daemon.
An OOB write in AOSP allows an attacker within NFC range to obtain remote code execution on android device's NFC daemon.
An OOB write in AOSP allows an attacker within NFC range to obtain remote code execution on android device's NFC daemon.
Improper sanitization of SQL queries lead to SQL injection via a configuration file.
The GitHub Security Labs team has identified a Use after free in Chrome WebAudio.
The GitHub Security Labs team has identified a Use after free in Chrome WebAudio.
The GitHub Security Labs team has identified a Use after free in Chrome WebAudio.
The GitHub Security Labs team has identified a Use after free in Chrome WebAudio.
The GitHub Security Labs team has identified a Use after free in Chrome WebAudio.
The GitHub Security Labs team has identified a Use after free in Chrome WebAudio.
Server-Side Template Injection in Dropwizard leading to Remote Code Execution (RCE).
High privileged users can bypass the existing mitigations and inject arbitrary Java EL expressions in Nexus Repository Manager, leading to a Remote Code Execution (RCE) vulnerability.
It is possible for a user with the right permissions to execute arbitrary groovy or javascript scripts resulting in remote code execution.
It is possible for a user with the right permissions to execute arbitrary groovy or javascript scripts resulting in remote code execution.
High privileged users can inject arbitrary Java EL expressions in Nexus Repository Manager, leading to a Remote Code Execution (RCE) vulnerability.
A use-after-free vulnerability in ProFTPD could allow a remote attacker to execute arbitrary code on the affected system.
An attacker with elevated privileges can create content selectors with a specially crafted name using the REST API, which when viewed by another user can execute arbitrary JavaScript in the context of the NXRM application.
Attackers can inject arbitrary Java EL expressions in Nexus Repository Manager, leading to a Remote Code Execution (RCE) vulnerability.
The GitHub Security Labs team has identified a security issue in OpenSSL in which an attacker can force a client into freeing the same memory twice.
A Server-Side Template Injection was identified in Netflix Titus enabling attackers to inject arbitrary Java EL expressions, leading to a pre-auth Remote Code Execution (RCE) vulnerability.
A Server-Side Template Injection was identified in Netflix Conductor enabling attackers to inject arbitrary Java EL expressions, leading to a pre-auth Remote Code Execution (RCE) vulnerability.
An out-of-bounds (OOB) read vulnerability has been detected in PureFTPd's pure_strcmp function.
Several security issues have been found in the way X509 certificate validation functions are exposed to LUA. Clients using certain functions in lua-openssl are exposed to person-in-the-middle attacks.
An uninitialized pointer vulnerability in PureFTPd results in Out-of-Bounds reads and Denial of Service.
Several security issues have been found in the way openfortivpn deals with TLS. These issues can lead to situations in which an attacker can perform a person-in-the-middle attack on clients.
An out-of-bounds (OOB) read vulnerability detected in mod_cap.
Under certain circumstances, an off-by-one heap overflow can occur in the command_retr function.