Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the fixed size of the filter's header. This allows attackers to cause a denial of service via a crafted HDF5 file that stores the N-Bit filter pipeline message with zero client-data values, opened and read via H5Dread, e.g. by the h5ls or h5repack tools.
H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 a
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An unauthenticated `POST /__nuxt_island/_.json` with a large JSON body is fully read, parsed, hashed, and then rejected, which wastes CPU on Nitro single event loop and delays concurrent requests. No valid hash and no authentic
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.