βΌ CVE-2021-33643 βΌ
π Read
via "National Vulnerability Database".
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35509 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32245 βΌ
π Read
via "National Vulnerability Database".
SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 430, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35524 βΌ
π Read
via "National Vulnerability Database".
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_EncrypTyp, sel_Automode, wlan_bssid, wlan_ssid and wlan_channel, which leads to command injection in page /wizard_rep.shtml.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35290 βΌ
π Read
via "National Vulnerability Database".
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.π Read
via "National Vulnerability Database".
βΌ CVE-2022-20348 βΌ
π Read
via "National Vulnerability Database".
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529π Read
via "National Vulnerability Database".
βΌ CVE-2022-35522 βΌ
π Read
via "National Vulnerability Database".
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: ppp_username, ppp_passwd, rwan_gateway, rwan_mask and rwan_ip, which leads to command injection in page /wan.shtml.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30633 βΌ
π Read
via "National Vulnerability Database".
Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.π Read
via "National Vulnerability Database".
βΌ CVE-2022-37024 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2457 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.π Read
via "National Vulnerability Database".
βΌ CVE-2022-37005 βΌ
π Read
via "National Vulnerability Database".
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32429 βΌ
π Read
via "National Vulnerability Database".
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33645 βΌ
π Read
via "National Vulnerability Database".
The th_read() function doesnΓ’β¬β’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30630 βΌ
π Read
via "National Vulnerability Database".
Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35697 βΌ
π Read
via "National Vulnerability Database".
Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires a low author privilege access.π Read
via "National Vulnerability Database".
βΌ CVE-2022-20357 βΌ
π Read
via "National Vulnerability Database".
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-214999987π Read
via "National Vulnerability Database".
βΌ CVE-2022-35534 βΌ
π Read
via "National Vulnerability Database".
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command injection in page /wifi_multi_ssid.shtml.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-35537 βΌ
π Read
via "National Vulnerability Database".
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injection in page /wifi_mesh.shtml.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36270 βΌ
π Read
via "National Vulnerability Database".
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.π Read
via "National Vulnerability Database".
β Podcast: Inside the Hackersβ Toolkit β
π Read
via "Threat Post".
This edition of the Threatpost podcast is sponsored by Egress.π Read
via "Threat Post".
βΌ CVE-2022-38161 βΌ
π Read
via "National Vulnerability Database".
The Gumstix Overo SBC on the VSKS board through 2022-08-09, as used on the Orlan-10 and other platforms, allows unrestricted remapping of the NOR flash memory containing the bitstream for the FPGA.π Read
via "National Vulnerability Database".