βΌ CVE-2022-38398 βΌ
π Read
via "National Vulnerability Database".
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40444 βΌ
π Read
via "National Vulnerability Database".
ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1941 βΌ
π Read
via "National Vulnerability Database".
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38648 βΌ
π Read
via "National Vulnerability Database".
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.π Read
via "National Vulnerability Database".
β S3 Ep101: Uber and LastPass breaches β is 2FA all itβs cracked up to be? [Audio + Text] β
π Read
via "Naked Security".
Latest episode - listen now! Learn why adopting 2FA isn't a reason to relax your other security precautions...π Read
via "Naked Security".
Naked Security
S3 Ep101: Uber and LastPass breaches β is 2FA all itβs cracked up to be? [Audio + Text]
Latest episode β listen now! Learn why adopting 2FA isnβt a reason to relax your other security precautionsβ¦
π Digital Guardian Named A Top Data Loss Prevention Solution by Expert Insights π
π Read
via "".
An independent editorial team and technical analysts praised Digital Guardian's quick deployment, on-demand scalability, and full visibility into data.π Read
via "".
βΌ CVE-2022-35037 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35029 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35032 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35024 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40934 βΌ
π Read
via "National Vulnerability Database".
Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,idπ Read
via "National Vulnerability Database".
βΌ CVE-2022-35021 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a global buffer overflow via /release-x64/otfccdump+0x718693.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35035 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39190 βΌ
π Read
via "National Vulnerability Database".
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35038 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b064d.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35026 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbc0b.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35022 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35023 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /lib/x86_64-linux-gnu/libc.so.6+0xbb384.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40935 βΌ
π Read
via "National Vulnerability Database".
Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35028 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35408 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSmm leads to possible arbitrary code execution in SMM and escalation of privileges. An attacker could overwrite the function pointers in the EFI_BOOT_SERVICES table before the USB SMI handler triggers. (This is not exploitable from code running in the operating system.)π Read
via "National Vulnerability Database".