βΌ CVE-2022-34800 βΌ
π Read
via "National Vulnerability Database".
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-34797 βΌ
π Read
via "National Vulnerability Database".
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34809 βΌ
π Read
via "National Vulnerability Database".
Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34805 βΌ
π Read
via "National Vulnerability Database".
Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34811 βΌ
π Read
via "National Vulnerability Database".
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33326 βΌ
π Read
via "National Vulnerability Database".
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/config_rollback/` API is affected by a command injection vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33087 βΌ
π Read
via "National Vulnerability Database".
A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31115 βΌ
π Read
via "National Vulnerability Database".
opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must be in control of an opensearch server and convince the victim to connect to it in order to exploit this vulnerability. The problem has been patched in opensearch-ruby gem version 2.0.1. Users are advised to upgrade. There are no known workarounds for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33082 βΌ
π Read
via "National Vulnerability Database".
An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33085 βΌ
π Read
via "National Vulnerability Database".
ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2274 βΌ
π Read
via "National Vulnerability Database".
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2279 βΌ
π Read
via "National Vulnerability Database".
NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2280 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.π Read
via "National Vulnerability Database".
ποΈ Latest web hacking tools β Q3 2022 ποΈ
π Read
via "The Daily Swig".
We take a look at the latest additions to security researchersβ armoryπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Latest web hacking tools β Q3 2022
We take a look at the latest additions to security researchersβ armory
βΌ CVE-2022-34894 βΌ
π Read
via "National Vulnerability Database".
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted servicesπ Read
via "National Vulnerability Database".
βΌ CVE-2022-2264 βΌ
π Read
via "National Vulnerability Database".
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.π Read
via "National Vulnerability Database".
ποΈ Gitlab patches critical RCE bug in latest security release ποΈ
π Read
via "The Daily Swig".
Users are urged to update to the latest versionπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Gitlab patches critical RCE bug in latest security release
Users are urged to update to the latest version
βΌ CVE-2022-33103 βΌ
π Read
via "National Vulnerability Database".
Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().π Read
via "National Vulnerability Database".
βΌ CVE-2022-33099 βΌ
π Read
via "National Vulnerability Database".
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2282 βΌ
π Read
via "National Vulnerability Database".
Improper Authorization in GitHub repository saltstack/salt prior to 3004.2.π Read
via "National Vulnerability Database".
π Queue Abstract Data Type Tool π
π Read
via "Packet Storm Security".
This tool can be embedded into AI systems for storing information and deleting it very efficiently by using queues disguising themselves as arrays and adding data and removing the data using pointers and flags.π Read
via "Packet Storm Security".
Packetstormsecurity
Queue Abstract Data Type Tool β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers