Software Engineering Institute
Computer Emergency Readiness Team
- VU#806555: A Vulnerability in UEFI Applications allows for secure boot bypass via misused NVRAM variable
- VU#282450: Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation
- VU#211341: A vulnerability in Insyde H2O UEFI application allows for digital certificate injection via NVRAM variable
- VU#760160: libexpat library is vulnerable to DoS attacks through stack overflow
- VU#722229: Radware Cloud Web Application Firewall Vulnerable to Filter Bypass
- VU#360686: Digigram PYKO-OUT audio-over-IP (AoIP) does not require a password by default
- VU#667211: Various GPT services are vulnerable to “Inception” jailbreak, allows for bypass of safety guardrails
- VU#252619: Multiple deserialization vulnerabilities in PyTorch Lightning 2.4.0 and earlier versions
- VU#726882: Paragon Partition Manager contains five memory vulnerabilities within its BioNTdrv.sys driver that allow for privilege escalation and denial-of-service (DoS) attacks
- VU#148244: PandasAI interactive prompt function can be exploited to run arbitrary Python code through prompt injection, which can lead to remote code execution (RCE)
- VU#733789: ChatGPT-4o contains security bypass vulnerability through time and search functions called “Time Bandit”
- VU#199397: Insecure Implementation of Tunneling Protocols (GRE/IPIP/4in6/6in4)
- VU#952657: Rsync contains six vulnerabilities
- VU#529659: Howyar Reloader UEFI Bootloader Vulnerable to Unsigned Software Execution