An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
A heap-buffer-overflow vulnerability in the readbyte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.
Null Pointer Dereference vulnerability in topicfiltern function in mqttparser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.
Buffer Overflow vulnerability in the getvarinteger function in mqttparser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams.
In NanoMQ v0.15.0-0, Heap overflow occurs in readbyte function of mqttcode.c.
In NanoMQ v0.15.0-0, a Heap overflow occurs in copynutf8str function of mqttparser.c
In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfodecode and unsubinfodecode.
UNSUPPORTED WHEN ASSIGNED EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid.