Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.js file.
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.
Code Injection in GitHub repository librenms/librenms prior to 23.9.0.
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
Buffer overflow vulnerability in Frhed hex editor, affecting version 1.6.0. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument through the Structured Exception Handler (SEH) registers.
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.