CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in file disclosure (i.e., being able to pull any file from the remote victim application). This can be used to steal and obtain sensitive config and other files. This can result in complete compromise of the application. The script parameter is vulnerable to directory traversal and both local and remote file inclusion.
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.
R700_laser_presentation_remote_firmware, R700_laser_presentation_remote, Unifying_receiver_firmware, Unifying_receiver, R500_firmware, R500, K360_firmware, K360
2019-07-08
N/A
6.5 MEDIUM
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard.
R700_laser_presentation_remote_firmware, R700_laser_presentation_remote, Unifying_receiver_firmware, Unifying_receiver, R500_firmware, R500, K360_firmware, K360
2020-08-24
N/A
6.5 MEDIUM
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.
R700_laser_presentation_remote_firmware, R700_laser_presentation_remote, Unifying_receiver_firmware, Unifying_receiver, R500_firmware, R500, K360_firmware, K360
2020-08-24
N/A
6.5 MEDIUM
Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists because of an incomplete fix for CVE-2016-10761.
R700_laser_presentation_remote_firmware, R700_laser_presentation_remote, Unifying_receiver_firmware, Unifying_receiver, R500_firmware, R500, K360_firmware, K360
2020-08-24
N/A
6.5 MEDIUM
Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
