Export limit exceeded: 399565 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399565 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102715 | 1 Eclipse | 1 Threadx Netx Duo | 2026-09-29 | N/A |
| Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF; ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...) ``` The lookup that decides whether an incoming name is already stored compares the rounded slot size, so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered with the pointer to the first, and the record then carries a string up to three bytes longer than the length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only bound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string. Two PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names whose lengths fall in the same bucket: ``` ==87491==ERROR: AddressSanitizer: heap-buffer-overflow WRITE of size 1 at 0x611000000124 thread T5 #0 _nx_mdns_name_string_encode addons/mdns/nxd_mdns.c:13096 #1 _nx_mdns_packet_rr_add addons/mdns/nxd_mdns.c:8911 0x611000000124 is 0 bytes to the right of 228-byte region ``` The overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash. Compare the slot size against the stored string length before declaring a match, or keep the string length in the slot header and return it to the caller so the encoder and the bound check agree. | ||||
| CVE-2026-102242 | 1 Google | 1 Mcp Toolbox For Databases | 2026-09-29 | N/A |
| Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories. | ||||
| CVE-2026-88059 | 1 Angular | 1 Angular | 2026-09-29 | 4 Medium |
| Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authenticated response when Server-Side Rendering (SSR) and hydration use a hierarchical HttpClient configured with withRequestsMadeViaParent. The child TransferCache evaluates an initially anonymous request before delegation, then a parent withInterceptors chain adds an Authorization header, cookie, or API token; although the parent cache skips the authenticated request, the child still stores the private response in TransferState serialized as JSON in the ng-state script. Exploitation requires provideClientHydration, child provideHttpClient delegation through withRequestsMadeViaParent, parent-level credential injection, and an SSR HTML response shared across users by a CDN, reverse proxy, or application cache. A later unauthenticated or unauthorized visitor can receive the cached HTML containing the earlier authenticated user's sensitive response data. Applications can mitigate by attaching credentials at the child, filtering sensitive endpoints with withHttpTransferCacheOptions, disabling transfer caching for sensitive routes, or marking personalized HTML private or no-store. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.1. | ||||
| CVE-2026-91191 | 2026-09-29 | 7.5 High | ||
| The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation. | ||||
| CVE-2026-19503 | 1 Mongodb | 4 Atlas Sql Odbc Driver, Odbc Driver, Schema Builder Cli and 1 more | 2026-09-29 | 4.8 Medium |
| MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context. | ||||
| CVE-2026-84409 | 2026-09-29 | 7.5 High | ||
| The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device. | ||||
| CVE-2026-84421 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-29 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction. | ||||
| CVE-2026-84436 | 1 Ibm | 1 Guardium Data Protection | 2026-09-29 | 9.1 Critical |
| IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges. | ||||
| CVE-2026-84842 | 1 Ibm | 1 Guardium Data Protection | 2026-09-29 | 8.1 High |
| IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity. | ||||
| CVE-2026-100299 | 2026-09-29 | 6.8 Medium | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption. | ||||
| CVE-2026-100298 | 2026-09-29 | 8.8 High | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation. | ||||
| CVE-2026-100297 | 2026-09-29 | 5.3 Medium | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak data via DNS queries. | ||||
| CVE-2026-100296 | 2026-09-29 | 8.1 High | ||
| In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it. | ||||
| CVE-2026-100295 | 2026-09-29 | 6.3 Medium | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access. | ||||
| CVE-2026-100294 | 2026-09-29 | 7.5 High | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation. | ||||
| CVE-2026-100293 | 2026-09-29 | 8.8 High | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid. | ||||
| CVE-2026-100292 | 2026-09-29 | 8.8 High | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler. | ||||
| CVE-2026-100291 | 2026-09-29 | 9.8 Critical | ||
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations. | ||||
| CVE-2026-96274 | 2026-09-29 | 7.4 High | ||
| In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity. | ||||
| CVE-2026-102712 | 2026-09-29 | N/A | ||
| On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing ServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first packet. | ||||