Draft in the CWE catalog ยท 9 CVEs mapped
The product contains dead code, which can never be executed.
A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests.
๐จ Danger lurks in the Docker containers! A script in Vasion Print can reset your entire database root password with just a single request, and it doesn't even require authentication! ๐ฅ Think of it like a restaurant where the chef leaves the kitchen door wide open and leaves the recipe book on the counter โ anyone can just waltz in, change the secret sauce, and serve whatever they want without anyone checking their ID. An attacker exploiting this vulnerability could simply reset the MySQL root password to 'password', gaining full control over your database. With access to sensitive information, they could manipulate data, steal credentials, or even take complete control of your system โ an absolutely devastating blow to your security!
Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.