CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
** UNSUPPORTED WHEN ASSIGNED ** CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPATH, to be dynamically linked when the emtgtctl2 executable is run. The code in the library will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
Heap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in ok_jpg.c.
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
An unlimited recursion in DxeCore in EDK II.
