Tag: denialOfService

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

  • Vulnerability Watch No42

    UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…

  • Vulnerability Watch No39

    Windows DHCP Client Heap Overflow Enables Privilege Escalation • Browserslist Cache Exhaustion Can Crash Processes • Browserslist Stats Parsing Opens Door to Crashes and Prototype Changes • Nanoid Integer Bug Can Make Security Tokens Predictable • Windows CLFS Race Condition Enables Local Privilege Escalation…

  • Vulnerability Watch No36

    GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads • GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution • Uasoft Badaso File API Permission Flaw Has Public Exploit • ipTIME AX8004M Command Injection Has Public Exploit • Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management…

  • Vulnerability Watch No33

    Bouncy Castle FIPS Key Zeroisation Can Fall Behind on Newer JVMs • Bouncy Castle FIPS Entropy Failure Can Hang Applications • Klever-Go REST APIs Exposed to Slow-Header Denial of Service • Klever-Go Peer Can Trigger Unbounded Goroutine Creation • Tiny Malformed Transaction Can Crash Klever-Go Nodes…

  • Vulnerability Watch No32

    go-git Symlink Escape Can Reach Files Outside Worktrees • ZenML Artifact Poisoning Enables Remote Code Execution • Absinthe Federation Atom Exhaustion Can Crash Erlang Nodes • ClamAV XAR Parser Memory Corruption Can Trigger DoS • Crafted Mach-O Files Can Crash ClamAV Scanners…

  • Vulnerability Watch No29

    Forminator Upload-Record Flaw Enables Stored XSS • File Manager Flaw Can Delete Server Files and Enable RCE • NanoClaw Path Traversal Exploit Is Public • LettaBot API Status Route Lacks Authentication • Super Agent Party Proxy Route Exposes SSRF Flaw…

  • Vulnerability Watch No28

    Cisco IOS XE Resource-Lifecycle Control Flaw • IBM Langflow MCP Endpoint Authentication Bypass • Cisco Catalyst SD-WAN File Access Link Flaw • Cisco Catalyst SD-WAN Stores Sensitive Data in Cleartext • Critical Cisco Catalyst SD-WAN Link Resolution Vulnerability…

  • Vulnerability Watch No27

    H3C NX15 Web API Exposes Dangerous Routine • UTT HiPER 1200GW Hit by Remote Buffer Overflow • UTT HiPER 1250GW TempName Overflow Exposed • UTT HiPER 1250GW 5 GHz Endpoint Overflow • ESAFENET CDG KeyID Parameter Enables SQL Injection…