ZeroHour

Vulnerabilities

22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-46433
lldpd is an implementation of IEEE 802.1ab (LLDP).

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.

NVD description · AI analysis pending
6.5<1%
  • lldpd project lldpd
CVE-2024-9350
The DPD Baltic Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_value' parameter in all versions up to, and includi

The DPD Baltic Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_value' parameter in all versions up to, and including, 1.2.83 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

NVD description · AI analysis pending
6.1<1%
  • dpd dpd baltic shipping
CVE-2023-41910
An issue was discovered in lldpd before 1.0.17.

An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.

NVD description · AI analysis pending
9.81%
  • lldpd project lldpd
CVE-2021-43612
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

NVD description · AI analysis pending
7.51%
  • lldpd project lldpd
  • lldpd project fedora
CVE-2022-3999
+1 in the same advisory: …4000
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such a

The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.

NVD description · AI analysis pending
8.1
group max
<1% PoC
  • dpdgroup woocommerce shipping
CVE-2022-2132
A permissive list of allowed inputs flaw was found in DPDK.

A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

NVD description · AI analysis pending
8.62% PoC ×2
  • dpdk data plane development kit
  • dpdk fedora
  • dpdk debian linux
  • +1 more
CVE-2022-0669
A flaw was found in dpdk.

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.

NVD description · AI analysis pending
6.5<1%
  • dpdk data plane development kit
  • dpdk openvswitch
  • dpdk openshift container platform
CVE-2021-3839
A flaw was found in the vhost library in DPDK.

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

NVD description · AI analysis pending
7.52%
  • dpdk data plane development kit
  • dpdk fedora
  • dpdk enterprise linux
  • +1 more
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch.

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

NVD description · AI analysis pending
7.53%
  • lldpd project lldpd
  • lldpd project openvswitch
  • lldpd project openshift container platform
  • +1 more
CVE-2020-14374
+4 in the same advisory: …14376 …14375 …14377 …14378
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5.

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to any address in the vhost_crypto application. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

NVD description · AI analysis pending
8.8
group max
<1%
  • dpdk data plane development kit
  • dpdk ubuntu linux
  • dpdk leap
CVE-2020-10725
+1 in the same advisory: …10726
A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on th

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

NVD description · AI analysis pending
7.7
group max
2%
  • dpdk data plane development kit
  • dpdk fedora
  • dpdk leap
  • +1 more
CVE-2020-10723
+2 in the same advisory: …10722 …10724
A memory corruption issue was found in DPDK versions 17.05 and above.

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

NVD description · AI analysis pending
6.7
group max
<1%
  • dpdk data plane development kit
  • dpdk ubuntu linux
  • dpdk fedora
  • +1 more
CVE-2019-14818
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

NVD description · AI analysis pending
7.53%
  • dpdk data plane development kit
  • dpdk enterprise linux fast datapath
  • dpdk openstack
  • +1 more
CVE-2018-1059
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addre

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

NVD description · AI analysis pending
6.1<1%
  • canonical ubuntu linux
  • canonical ceph storage
  • canonical enterprise linux fast datapath
  • +1 more