| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints. |
| IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672601; Issue ID: MSV-4623. |
| The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specially crafted input. This can result in the injection of arbitrary properties into the Object.prototype, potentially leading to denial of service conditions or unexpected application behavior. The vulnerability allows attackers to alter the prototype of base objects, impacting all subsequent object instances throughout the application's lifecycle. |
| Transient DOS while processing video packets received from video firmware. |
| Information disclosure while processing batch command execution in Video driver. |
| Memory corruption while processing camera platform driver IOCTL calls. |
| Transient DOS while processing IOCTL call for image encoding. |
| Memory corruption during PlayReady APP usecase while processing TA commands. |
| Memory corruption while processing a malformed license file during reboot. |
| Memory corruption while processing escape commands from userspace. |
| Memory corruption while processing IOCTL call to get the mapping. |
| memory corruption while processing an image encoding completion event. |
| Memory corruption while processing an escape call. |
| Memory corruption while processing user buffers. |
| Memory corruption while allocating buffers in DSP service. |
| Memory corruption while invoking remote procedure IOCTL calls. |
| An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. |
| An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function |
| NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. |