py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() ...
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A re...
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/...
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) ...
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree to redirect file reads to unintended paths. Attackers ...
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.