Vulnerabilities (CVE)

Filtered by CWE-228
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-6382 2024-07-03 N/A 6.4 MEDIUM
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2
CVE-2024-22815 2024-07-03 N/A 5.3 MEDIUM
An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) via crafted commands.
CVE-2024-22809 2024-07-03 N/A 6.5 MEDIUM
Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and view sensitive information.
CVE-2021-38443 1 Eclipse 1 Cyclonedds 2024-02-04 7.5 HIGH 9.8 CRITICAL
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
CVE-2020-27847 1 Linuxfoundation 1 Dex 2024-02-04 7.5 HIGH 9.8 CRITICAL
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.