Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2024-25763
openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
Opennds
No fix yet
CRITICAL 9.8
CVE-2023-38319
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have dire…
Opennds
10.1.3+
CRITICAL 9.8
CVE-2023-38323
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers tha…
Opennds
10.1.3+
CRITICAL 9.8
CVE-2023-38317
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers…
Opennds
10.1.3+
CRITICAL 9.8
CVE-2023-38318
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have…
Opennds
10.1.3+
CRITICAL 9.8
CVE-2023-41101
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the qu…
Opennds
10.1.3+
HIGH 7.5
CVE-2023-41102
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. …
Opennds
10.1.3+
CRITICAL 9.8
CVE-2023-38316
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrar…
Captive Portal
10.1.2+
HIGH 7.5
CVE-2023-38313
An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GE…
Captive Portal
10.1.2+
HIGH 7.5
CVE-2023-38315
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered …
Captive Portal
10.1.2+
HIGH 7.5
CVE-2023-38320
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered wit…
Captive Portal
10.1.2+
HIGH 7.5
CVE-2023-38322
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafte…
Captive Portal
10.1.2+
MEDIUM 6.5
CVE-2023-38314
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggere…
Captive Portal
10.1.2+
MEDIUM 5.3
CVE-2023-38324
An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the d…
Captive Portal
10.1.2+