CWE-170
Improper Null Termination
Produkt nie zakańcza lub nieprawidłowo zakańcza ciąg znaków lub tablicę znakiem null lub równoważnym terminatorem. Może to prowadzić do przekroczenia granic buforu i innych problemów bezpieczeństwa.
The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.
Wiele podatności w aplikacji Cisco Jabber na platformy Windows, MacOS oraz mobilne umożliwia atakującemu wykonanie dowolnego kodu z podwyższonymi uprawnieniami, przechwycenie ruchu sieciowego lub wywołanie stanu DoS. Podatności otrzymały ocenę CVSS 9.9, co klasyfikuje je jako krytyczne.
Wiele podatności w Cisco Jabber dla systemów Windows, MacOS oraz platform mobilnych umożliwia atakującemu wykonanie dowolnych programów z podwyższonymi uprawnieniami, przechwycenie ruchu sieciowego lub wywołanie stanu odmowy usługi (DoS). Wysoki wynik CVSS 9.9 wskazuje na krytyczny poziom zagrożenia dla organizacji korzystających z tego komunikatora.
Cisco Jabber dla Windows, MacOS i platform mobilnych zawiera wiele podatności, które mogą pozwolić atakującemu na wykonanie dowolnego kodu z podwyższonymi uprawnieniami, przechwycenie ruchu sieciowego lub wywołanie stanu DoS. Krytyczny wynik CVSS 9.9 wskazuje na bardzo wysokie ryzyko dla organizacji korzystających z tego komunikatora.
Cisco Jabber dla systemów Windows, MacOS oraz platform mobilnych zawiera wiele podatności, które mogą pozwolić atakującemu na wykonanie dowolnego kodu z podwyższonymi uprawnieniami lub przechwycenie ruchu sieciowego. Wysoki wynik CVSS 9.9 wskazuje na krytyczny poziom zagrożenia dla organizacji korzystających z tego oprogramowania.
Cisco Jabber dla systemów Windows, MacOS oraz platform mobilnych zawiera wiele podatności, które mogą umożliwić atakującemu wykonanie dowolnego kodu z podwyższonymi uprawnieniami, przechwycenie ruchu sieciowego lub wywołanie stanu DoS. Podatności uzyskały krytyczny poziom zagrożenia z wynikiem CVSS 9.9.
Podatność w serwerze HTTP systemu Zephyr RTOS umożliwia zdalnemu, nieuwierzytelnionemu atakującemu wywołanie uszkodzenia pamięci stosu poprzez spreparowany nagłówek Sec-WebSocket-Key podczas negocjacji WebSocket. Błąd może prowadzić do odmowy usługi (DoS) lub potencjalnie do zdalnego wykonania kodu (RCE).
Biblioteka Crypt::OpenSSL::PKCS12 dla Perl w wersjach do 1.94 po cichu obcina hasła zawierające wbudowane bajty NULL, odrzucając wszystko co następuje po pierwszym znaku NUL. Skutkuje to znaczącym zmniejszeniem entropii haseł bez jakiegokolwiek ostrzeżenia dla użytkownika lub aplikacji.
Podatność w kliencie DHCP wbudowanym w oprogramowanie Siemens Nucleus oraz powiązane produkty umożliwia zdalne odczytywanie i zapisywanie danych poza dozwolonym obszarem pamięci. Oceniona jako krytyczna (CVSS 9.8), może prowadzić do przejęcia kontroli nad urządzeniem lub jego niedostępności bez jakiegokolwiek uwierzytelnienia.
Serwer FTP wbudowany w stos sieciowy Siemens Nucleus NET nie weryfikuje poprawnie długości komendy 'USER', co prowadzi do stack-based buffer overflow. Podatność o ocenie CVSS 9.8 umożliwia zdalne wykonanie kodu (RCE) bez uwierzytelnienia.
Node.js w wersjach przed 16.6.0, 14.17.4 i 12.22.4 nie waliduje poprawnie nazw hostów zwracanych przez serwery DNS, co umożliwia zdalne wykonanie kodu (RCE) oraz ataki XSS. Podatność jest krytyczna ze względu na możliwość przejęcia kontroli nad aplikacją bez uwierzytelnienia.
UltraVNC w rewizji 1211 zawiera wiele podatności polegających na nieprawidłowym zakończeniu ciągów znaków (improper null termination) w kodzie serwera VNC. Błędy te pozwalają zdalnym, nieuwierzytelnionym użytkownikom na dostęp do danych spoza dozwolonych obszarów pamięci, co czyni tę podatność krytyczną.
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed WCHAR pipename[160] stack buffer using wcscat without verifying null termination. The handler only enforces a minimum packet size, and since the service pipe accepts variable-length messages, a sandboxed caller can fill the server[48] field with non-zero data and append additional controlled wide characters after the structure. wcscat then reads past the fixed field and overflows the stack buffer in the SYSTEM service. This message is restricted to sandboxed callers, making it a sandbox escape vector. This can lead to a crash of the SbieSvc service or potential code execution as SYSTEM. This issue has been fixed in version 1.17.3.
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC100-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC12-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC128-U (All versions >= V2.3 and < V6.30.016), Desigo PXC200-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC36.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC50-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC64-U (All versions >= V2.3 and < V6.30.016), Desigo PXM20-E (All versions >= V2.3 and < V6.30.016), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions < V3.5.4), TALON TC Modular (BACnet) (All versions < V3.5.4). FTP server does not properly validate the length of the “PWD/XPWD” command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Remote Code Execution. (FSMD-2021-0016)
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC100-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC12-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC128-U (All versions >= V2.3 and < V6.30.016), Desigo PXC200-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC36.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC50-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC64-U (All versions >= V2.3 and < V6.30.016), Desigo PXM20-E (All versions >= V2.3 and < V6.30.016), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions < V3.5.4), TALON TC Modular (BACnet) (All versions < V3.5.4). FTP server does not properly validate the length of the “MKD/XMKD” command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Remote Code Execution. (FSMD-2021-0018)
A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source.
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.
A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.
Windows USB Print Driver Elevation of Privilege Vulnerability
Microsoft SQL Server Information Disclosure Vulnerability
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string.