βΌ CVE-2021-32929 βΌ
π Read
via "National Vulnerability Database".
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28074 βΌ
π Read
via "National Vulnerability Database".
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27404 βΌ
π Read
via "National Vulnerability Database".
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27406 βΌ
π Read
via "National Vulnerability Database".
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32927 βΌ
π Read
via "National Vulnerability Database".
An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1437 βΌ
π Read
via "National Vulnerability Database".
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27405 βΌ
π Read
via "National Vulnerability Database".
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36203 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in all versions of SCT/SCT Pro prior to version 14.2.2 allows a remote unauthenticated attacker to identify and forge requests to internal systems via a specially crafted request allowing the attacker to determine if specific files or paths exist. This issue affects all versions of SCT/SCT Pro prior to version 14.2.2.π Read
via "National Vulnerability Database".
π Friday Five 4/22 π
π Read
via "".
The thwarting of an underwater cyber attack, a growing cyber threat to critical infrastructure, and phishing attacks leveragingβ¦ LinkedIn? Catch up on these stories and more with this weekβs Friday Five!π Read
via "".
Digital Guardian
Friday Five 4/22
The thwarting of an underwater cyber attack, a growing cyber threat to critical infrastructure, and phishing attacks leveragingβ¦ LinkedIn? Catch up on these stories and more with this weekβs Friday Five!
βΌ CVE-2020-14123 βΌ
π Read
via "National Vulnerability Database".
There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2021-29824 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38946 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38905 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20464 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38904 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1439 βΌ
π Read
via "National Vulnerability Database".
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38886 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38903 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 209691.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29582 βΌ
π Read
via "National Vulnerability Database".
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29583 βΌ
π Read
via "National Vulnerability Database".
service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29589 βΌ
π Read
via "National Vulnerability Database".
Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.π Read
via "National Vulnerability Database".
π1