CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Adequate, Advanced_package_tool, Amaya, Apache2, Apt, Apt-cacher, Aptlinex, Apt-listchanges, Apt-setup, Axiom, 389_administration_server, 389_directory_server, Anaconda, Arm_installer, Atomic, Commons, Coolkey, Crypto-utils, Dracut, Extra_packages_for_enterprise_linux, Ntfs-3g
2022-09-19
N/A
7.8 HIGH
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2023-02-01
N/A
7.5 HIGH
Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2022-05-23
N/A
7.5 HIGH
Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2022-05-23
N/A
7.5 HIGH
The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2022-05-23
N/A
9.8 CRITICAL
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2022-07-12
N/A
5.3 MEDIUM
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.
Adequate, Advanced_package_tool, Amaya, Apache2, Apt, Apt-cacher, Aptlinex, Apt-listchanges, Apt-setup, Axiom
2023-01-19
N/A
6.5 MEDIUM
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
