Vulnerabilities (CVE)

Filtered by CWE-242
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40698 1 Adobe 1 Coldfusion 2023-11-07 N/A 7.4 HIGH
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass  . An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
CVE-2017-1002157 1 Redhat 1 Modulemd 2023-03-01 7.5 HIGH 9.8 CRITICAL
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
CVE-2022-36310 1 Airspan 2 Airvelocity 1500, Airvelocity 1500 Firmware 2022-08-17 N/A 8.8 HIGH
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models.
CVE-2021-42543 1 Azeotech 1 Daqfactory 2021-11-08 7.5 HIGH 7.8 HIGH
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.
CVE-2017-0904 1 Private Address Check Project 1 Private Address Check 2019-10-09 6.8 MEDIUM 8.1 HIGH
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.