βΌ CVE-2022-25512 βΌ
π Read
via "National Vulnerability Database".
FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25511 βΌ
π Read
via "National Vulnerability Database".
An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0280 βΌ
π Read
via "National Vulnerability Database".
A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted and potentially cause denial of service. This attack exploits the way symlinks are created and how the product works with them.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0821 βΌ
π Read
via "National Vulnerability Database".
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0815 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the userΓ’β¬β’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25507 βΌ
π Read
via "National Vulnerability Database".
FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0820 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25506 βΌ
π Read
via "National Vulnerability Database".
FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25510 βΌ
π Read
via "National Vulnerability Database".
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25508 βΌ
π Read
via "National Vulnerability Database".
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0822 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22151 βΌ
π Read
via "National Vulnerability Database".
CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23401 βΌ
π Read
via "National Vulnerability Database".
The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22729 βΌ
π Read
via "National Vulnerability Database".
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".
βΌ CVE-2022-21194 βΌ
π Read
via "National Vulnerability Database".
The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".
βΌ CVE-2022-21177 βΌ
π Read
via "National Vulnerability Database".
There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, andfrom R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0912 βΌ
π Read
via "National Vulnerability Database".
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26878 βΌ
π Read
via "National Vulnerability Database".
drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated but not freed).π Read
via "National Vulnerability Database".
βΌ CVE-2022-21808 βΌ
π Read
via "National Vulnerability Database".
Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22141 βΌ
π Read
via "National Vulnerability Database".
'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22145 βΌ
π Read
via "National Vulnerability Database".
CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.π Read
via "National Vulnerability Database".