External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. T...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sq...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- High
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code ex...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary c...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code e...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass....
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// or http://...
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- High
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain ca...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key name...
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
A cross-site scripting vulnerability in
queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because...
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- Low
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities....
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compar...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loo...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/Microsoft...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking th...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounde...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- Low
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- Low
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded UR...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size check to the comple...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- High
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to...
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-spec...
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without c...
- Attack vector
- Local
- Attack complexity
- High
- Privileges required
- None
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated...
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- Low
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privi...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/sc...
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- Low
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and resolveGoogleMapsU...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationCont...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters section. The Abs...
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKe...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javas...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment,...
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- Low
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix compar...
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comm...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.g...
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directo...
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- High
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in...
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise...
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- High
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- High
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
- Attack vector
- Adjacent network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
- Attack vector
- Adjacent network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- High
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- High
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
- Attack vector
- Adjacent network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory.
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- Low
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an array size field.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None