The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install.
The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames.
Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it.
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
Приведу 7 отличий, которые было бы неплохо знать. Читать далее