CERT Coordination Center

kb.cert.org

Imported from official source

Carnegie Mellon SEI vulnerability coordination centre.

Type
Research institution
Scope
US · global
Website
kb.cert.org
Feed
Atom

Publications 26

  1. VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations

    An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including w...

    Advisory Cybersecurity
  2. VU#762428: Authlib library contains a signature‑verification bypass vulnerability

    Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() fun...

    Advisory Cybersecurity
  3. VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

    Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exp...

    Advisory Cybersecurity
  4. VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise

    ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. ViewSonic ViewBoards a...

    Advisory Cybersecurity
  5. VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability

    Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identificati...

    Advisory Cybersecurity 2 versions
  6. VU#273940: Enterprise Access Management EAM does not rotate RSA keys

    Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The prod...

    Advisory Cybersecurity 2 versions
  7. VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

    Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or ov...

    Advisory Cybersecurity 3 versions
  8. VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

    Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate...

    Advisory Cybersecurity 2 versions
  9. VU#280377: Dokploy is vulnerable to OS command injection

    Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability s...

    Advisory Cybersecurity 3 versions
  10. VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

    Two vulnerabilities in MLflow’s dspy and statsmodels model flavors allow unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies...

    Advisory Cybersecurity 4 versions
  11. VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

    A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution withi...

    Advisory Cybersecurity 3 versions
  12. VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index

    An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful explo...

    Advisory Cybersecurity 3 versions
  13. VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks

    An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physic...

    Advisory Cybersecurity 3 versions
  14. VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

    The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot pro...

    Advisory Cybersecurity 3 versions
  15. VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

    Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed int...

    Advisory Cybersecurity 3 versions
  16. VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

    A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate ...

    Advisory Cybersecurity 3 versions
  17. VU#889462: Casdoor authentication server is vulnerable to authorization bypass

    Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions up to v4.2.0. The vulnerability allows a n...

    Advisory Cybersecurity 4 versions
  18. VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

    A vulnerability in the Hugging Face Transformers library (versions 4.57.0 to 5.16.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The ...

    Advisory Cybersecurity 4 versions
  19. VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

    Overview The Kaltura HTML5 Player V2 Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote cod...

    Advisory Cybersecurity 2 versions
  20. VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow

    Overview Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitra...

    Advisory Cybersecurity 2 versions
  21. VU#756733: Retraction of "Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability"

    Overview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on th...

    Advisory Cybersecurity 2 versions
  22. VU#874418: RDK-B WebUI contains multiple vulnerabilities

    Overview RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input vali...

    Advisory Cybersecurity 2 versions
  23. VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

    Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A ti...

    Advisory Cybersecurity 2 versions
  24. VU#614868: OpenCart ecommerce platform contains directory traversal vulnerability

    Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as...

    Advisory Cybersecurity
  25. VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability

    Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to ...

    Advisory Cybersecurity
  26. VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations

    Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iC...

    Advisory Cybersecurity

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.