| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contain __proto__ or constructor, causing nested writes to reach Object.prototype in the main n8n process and disrupt later requests. The affected function is summarizeWorkflowStructure in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts. This issue is fixed in versions 2.37.7 and 2.38.2. |
| n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern ^(./).git(/.)$ allowed catastrophic backtracking and ran synchronously in the main n8n process. An authenticated workflow editor could therefore freeze the instance with one workflow execution; the affected default is declared in packages/@n8n/config/src/configs/security.config.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2. |
| Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
| Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
| Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. |
| Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. |
| Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. |
| Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. |