NA - CVE-2022-3874 - A command injection flaw was found in foreman....
A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS...
NA - CVE-2023-34319 - The fix for XSA-423 added logic to...
The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that not all of the headers would come in one piece. Unfortunately the...
NA - CVE-2023-5002 - A flaw was found in pgAdmin. This issue occurs...
A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. Versions of...
NA - CVE-2022-4039 - A flaw was found in Red Hat Single Sign-On for...
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to...
NA - CVE-2023-23766 - An incorrect comparison vulnerability was...
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker...
NA - CVE-2023-42798 - AutomataCI is a template git repository...
AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1.4.1 and below can let a release job reset the git root repository to the...
NA - CVE-2023-42811 - aes-gcm is a pure Rust implementation of the...
aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext...
NA - CVE-2023-41027 - Credential disclosure in the...
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for...
NA - CVE-2023-41029 - Command injection vulnerability in the...
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute...