
hnsecurity/vulns
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 8.4 HIGH | — | ||
A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2. | |||
| 8.4 HIGH | — | ||
A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2. | |||
| 8.4 HIGH | — | ||
drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow. | |||
| 7.5 HIGH | — | ||
RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;" in calc_random in drivers/misc/rt_random.c. | |||
| 8.4 HIGH | — | ||
A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2. | |||
| 8.4 HIGH | — | ||
A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2. | |||
| 5.9 MEDIUM | — | ||
An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2. | |||
| 9.8 CRITICAL | — | ||
A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2. | |||
| 4.3 MEDIUM | — | ||
A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character. | |||
| 8.8 HIGH | — | ||
A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2. | |||
| 7.8 HIGH | — | ||
A stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-privileged users via the dtprintinfo setuid binary to escalate their privileges to root on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||
| 7.1 HIGH | — | ||
dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection allows those users to manipulate the control flow and disclose memory contents on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||