The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
Memory corruption in HAB Memory management due to broad system privileges via physical address.
Memory corruption in Graphics while importing a file.
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
Information disclosure due to buffer over-read in Modem while parsing DNS hostname.
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.