NA - CVE-2024-1523 - EC-WEB FS-EZViewer(Web)'s query...
EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying,...
Critical - CVE-2024-26260 - The functionality for synchronization in HGiga...
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request...
Critical - CVE-2024-26261 - The functionality for file download in HGiga...
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters,...
High - CVE-2024-26262 - EBM Technologies Uniweb/SoliPACS...
EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for...
Medium - CVE-2024-26263 - EBM Technologies RISWEB's specific URL...
EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.
Critical - CVE-2024-26264 - EBM Technologies RISWEB's specific query...
EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL...
NA - CVE-2022-23084 - The total size of the user-provided nmreq to...
The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On...
NA - CVE-2022-23085 - A user-provided integer option was passed to...
A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to kernel memory corruption. On systems configured...
NA - CVE-2022-23086 - Handlers for *_CFG_PAGE read / write ioctls in...
Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be...
NA - CVE-2022-23087 - The e1000 network adapters permit a variety of...
The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP and TCP checksums, insertion of an Ethernet VLAN...