Author: Angelo Barbosa

CVE-2024-30632 | Tenda FH1205 2.0.0.7(775) /goform/WifiBasicSet formWifiBasicSet security_5g stack-based overflow

A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer overflow. This vulnerability is known as CVE-2024-30632. The attack can be launched remotely. Furthermore, there is an exploit...

Read More

CVE-2024-30631 | Tenda FH1205 2.0.0.7(775) /goform/openSchedWifi setSchedWifi schedStartTime stack-based overflow

A vulnerability, which was classified as critical, was found in Tenda FH1205 2.0.0.7(775). Affected is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to stack-based buffer overflow. This vulnerability is traded as CVE-2024-30631. It is possible to launch the attack remotely. Furthermore, there is an exploit...

Read More

CVE-2023-52629 | Linux Kernel up to 2.6.20/6.5.3 push-switch flush_work use after free (610dbd8ac271/246f80a0b17f)

A vulnerability was found in Linux Kernel up to 2.6.20/6.5.3. It has been rated as critical. This issue affects the function flush_work of the component push-switch. The manipulation leads to use after free. The identification of this vulnerability is CVE-2023-52629. The attack can only be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-2409 | stylemix MasterStudy LMS WordPress Plugin up to 3.3.1 on WordPress _register_user improper authentication

A vulnerability was found in stylemix MasterStudy LMS WordPress Plugin up to 3.3.1 on WordPress. It has been declared as critical. This vulnerability affects the function _register_user. The manipulation leads to improper authentication. This vulnerability was named CVE-2024-2409. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2017-20191 | Zimbra zm-admin-ajax up to 8.8.1 Form Textbox Field Error XFormItem.js XFormItem.prototype.setError message cross site scripting

A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js of the component Form Textbox Field Error Handler. The manipulation of the argument message leads to cross site scripting. This vulnerability is uniquely identified as CVE-2017-20191. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More