Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
advertisement vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-32154
Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent malicious users to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The ...
NA
CVE-2024-23191
Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciou...
NA
CVE-2023-6200
A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent network could send an ICMPv6 router advertisement packet, causing arbitrary code execution.
Linux Linux Kernel 6.7
Linux Linux Kernel
NA
CVE-2023-5366
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local malicious user to create specially crafted packets with a modified or spoofed target IP address field that can redire...
Openvswitch Openvswitch
Redhat Enterprise Linux 7.0
Redhat Virtualization 4.0
Redhat Openshift Container Platform 4.0
Redhat Fast Datapath -
NA
CVE-2023-23759
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impac...
Facebook Fizz
NA
CVE-2020-35473
An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 up to and including 5.2, and extended scan response in Bluetooth Core Specifications 5.0 up to and including 5.2, may be used to identify devices usin...
Bluetooth Bluetooth Core Specification
NA
CVE-2022-20823
A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote malicious user to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 pac...
Cisco Nexus 3016 Firmware -
Cisco Nexus 3016q Firmware -
Cisco Nexus 3048 Firmware -
Cisco Nexus 3064 Firmware -
Cisco Nexus 3064-32t Firmware -
Cisco Nexus 3064-t Firmware -
Cisco Nexus 3064-x Firmware -
Cisco Nexus 3064t Firmware -
Cisco Nexus 3064x Firmware -
Cisco Nexus 3100 Firmware -
Cisco Nexus 3100-v Firmware -
Cisco Nexus 3100-z Firmware -
Cisco Nexus 3100v Firmware -
Cisco Nexus 31108pc-v Firmware -
Cisco Nexus 31108pv-v Firmware -
Cisco Nexus 31108tc-v Firmware -
Cisco Nexus 31128pq Firmware -
Cisco Nexus 3132c-z Firmware -
Cisco Nexus 3132q Firmware -
Cisco Nexus 3132q-v Firmware -
Cisco Nexus 3132q-x Firmware -
Cisco Nexus 3132q-x\\/3132q-xl Firmware -
5
CVSSv2
CVE-2022-27881
engine.c in slaacd in OpenBSD 6.9 and 7.0 prior to 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.
Openbsd Openbsd 7.0
Openbsd Openbsd 6.9
5
CVSSv2
CVE-2022-27882
slaacd in OpenBSD 6.9 and 7.0 prior to 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.
Openbsd Openbsd 6.9
Openbsd Openbsd 7.0
3.5
CVSSv2
CVE-2021-43032
In XenForo up to and including 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.
Xenforo Xenforo
1 Github repository
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »