cmu
Communicationsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting cmu.
- CVE-2026-35467Private Key stored as extractable in browser IndexeDB7.5
- CVE-2026-35466Stored XSS via unsanitized input from remote service6.1
- CVE-2026-22188Panda3D <= 1.10.16 Deploy-Stub Stack Exhaustion via Unbounded alloca()5.5
- CVE-2026-22190Panda3D <= 1.10.16 egg-mkfont Format String Information Disclosure7.5
- CVE-2026-22189Panda3D <= 1.10.16 egg-mkfont Stack Buffer Overflow9.8
- CVE-2025-27092Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint7.5
- CVE-2022-31506The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.9.3
- CVE-2014-7723The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers...5.4
- CVE-2014-0027The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tmp/awb.wav. NOTE: some of these details are obtained from...3.3
- CVE-2013-4122Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemented in glibc 2.17 and later, which allows remote attacke...4.3
- CVE-2011-3208Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a cra...7.5
- CVE-2011-3481The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer derefere...4.3
- CVE-2011-1926The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sendin...5.1
- CVE-2009-2632Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users ...4.4
- CVE-2009-0663Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an applicati...7.5