โผ CVE-2022-3461 โผ
๐ Read
via "National Vulnerability Database".
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43967 โผ
๐ Read
via "National Vulnerability Database".
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multilingual report due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43688 โผ
๐ Read
via "National Vulnerability Database".
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in icons since the Microsoft application tile color is not sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32266 โผ
๐ Read
via "National Vulnerability Database".
DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. The attack would require detailed knowledge of the PCD database contents on the current platform. This issue was discovered by Insyde engineering during a security review. This issue is fixed in Kernel 5.3: 05.36.23, Kernel 5.4: 05.44.23, Kernel 5.5: 05.52.23. Kernel 5.2 is unaffected. CWE-787 An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the parameter buffer that is used by a software SMI handler (used by the PcdSmmDxe driver) could lead to a TOCTOU race-condition attack on the SMI handler, and lead to corruption of other ACPI fields and adjacent memory fields. The attack would require detailed knowledge of the PCD database contents on the current platform.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43689 โผ
๐ Read
via "National Vulnerability Database".
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-35719 โผ
๐ Read
via "National Vulnerability Database".
IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-40309 โผ
๐ Read
via "National Vulnerability Database".
Users with write permissions to a repository can delete arbitrary directories.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-45390 โผ
๐ Read
via "National Vulnerability Database".
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-3480 โผ
๐ Read
via "National Vulnerability Database".
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IPรขโฌโขs. Configuring firewall limits for incoming connections cannot prevent the issue.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43686 โผ
๐ Read
via "National Vulnerability Database".
In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).๐ Read
via "National Vulnerability Database".
โผ CVE-2022-3964 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/rpzaenc.c of the component QuickTime RPZA Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. It is possible to initiate the attack remotely. The name of the patch is 92f9b28ed84a77138105475beba16c146bdaf984. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213543.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-37290 โผ
๐ Read
via "National Vulnerability Database".
GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-42132 โผ
๐ Read
via "National Vulnerability Database".
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-3971 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version 0.36.0 is able to address this issue. The name of the patch is 179313a37f06b298150edba3e2b0e5a73c1415e7. It is recommended to upgrade the affected component. VDB-213550 is the identifier assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-20946 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory handling error that occurs when GRE traffic is processed. An attacker could exploit this vulnerability by sending a crafted GRE payload through an affected device. A successful exploit could allow the attacker to cause the device to restart, resulting in a DoS condition. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM"] This advisory is part of the November 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-45400 โผ
๐ Read
via "National Vulnerability Database".
Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-30768 โผ
๐ Read
via "National Vulnerability Database".
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-42978 โผ
๐ Read
via "National Vulnerability Database".
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-3970 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43687 โผ
๐ Read
via "National Vulnerability Database".
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successful OAuth authentication. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-12507 โผ
๐ Read
via "National Vulnerability Database".
In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL injection. This may result in loss of confidentiality, loss of integrity and DoS.๐ Read
via "National Vulnerability Database".