CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2023-01-12
N/A
7.5 HIGH
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2023-01-12
N/A
7.5 HIGH
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2023-01-09
N/A
7.5 HIGH
The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2022-11-10
N/A
7.5 HIGH
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2022-11-10
N/A
9.8 CRITICAL
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
2022-10-25
N/A
7.2 HIGH
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29421. Reason: This candidate is a duplicate of CVE-2021-29421. Notes: All CVE users should reference CVE-2021-29421 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
