CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
An issue was discovered in FNET through 4.6.4. The code for processing resource records in mDNS queries doesn't check for proper ' ' termination of the resource record name string, leading to an out-of-bounds read, and potentially causing information leak or Denial-or-Service.
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
