Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2024-25763 openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c. Opennds No fix yet Fix from $1,6002024-02-26 CRITICAL 9.8 CVE-2023-38319 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have dire… Opennds 10.1.3+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2023-38323 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers tha… Opennds 10.1.3+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2023-38317 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers… Opennds 10.1.3+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2023-38318 An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have… Opennds 10.1.3+ Fix from $2,3002024-01-26 CRITICAL 9.8 CVE-2023-41101 An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the qu… Opennds 10.1.3+ Fix from $2,3002023-11-17 HIGH 7.5 CVE-2023-41102 An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. … Opennds 10.1.3+ Fix from $1,9502023-11-17 CRITICAL 9.8 CVE-2023-38316 An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrar… Captive Portal 10.1.2+ Fix from $2,3002023-11-17 HIGH 7.5 CVE-2023-38313 An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GE… Captive Portal 10.1.2+ Fix from $1,9502023-11-17 HIGH 7.5 CVE-2023-38315 An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered … Captive Portal 10.1.2+ Fix from $1,9502023-11-17 HIGH 7.5 CVE-2023-38320 An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered wit… Captive Portal 10.1.2+ Fix from $1,9502023-11-17 HIGH 7.5 CVE-2023-38322 An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafte… Captive Portal 10.1.2+ Fix from $1,9502023-11-17 MEDIUM 6.5 CVE-2023-38314 An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggere… Captive Portal 10.1.2+ Fix from $1,6002023-11-17 MEDIUM 5.3 CVE-2023-38324 An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the d… Captive Portal 10.1.2+ Fix from $1,6002023-11-17