‼ CVE-2022-36227 ‼
📖 Read
via "National Vulnerability Database".
In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference or, in some cases, even arbitrary code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41223 ‼
📖 Read
via "National Vulnerability Database".
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41940 ‼
📖 Read
via "National Vulnerability Database".
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-35407 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of the second variable exceeds the size of the first, then the buffer will be overwritten. This issue affects the SetupUtility driver of InsydeH2O.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-43214 ‼
📖 Read
via "National Vulnerability Database".
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36179 ‼
📖 Read
via "National Vulnerability Database".
Fusiondirectory 1.3 suffers from Improper Session Handling.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40842 ‼
📖 Read
via "National Vulnerability Database".
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41326 ‼
📖 Read
via "National Vulnerability Database".
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41937 ‼
📖 Read
via "National Vulnerability Database".
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and 13.10.8. As a workaround, setting the right of the page Filter.WebHome and making sure only the main wiki administrators can view the application installed on main wiki or edit the page and apply the changed described in commit fb49b4f.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-43215 ‼
📖 Read
via "National Vulnerability Database".
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40602 ‼
📖 Read
via "National Vulnerability Database".
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37931 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-36180 ‼
📖 Read
via "National Vulnerability Database".
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4111 ‼
📖 Read
via "National Vulnerability Database".
What happens if a bot net starts uploading 100MB files from 100 machines at the same time. This would mean that our network pipes are clogged handling 10GB of data while slowing down our real customers..... the answer the site will down and come not available📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40189 ‼
📖 Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue affects Pig Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Pig Provider is installed (Pig Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Pig Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40954 ‼
📖 Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files. This issue affects Spark Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Spark Provider is installed (Spark Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Spark Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version that has lower version of the Spark Provider installed).📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41131 ‼
📖 Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to 4.1.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case HIve Provider is installed (Hive Provider 4.1.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the HIve Provider version 4.1.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version that has lower version of the Hive Provider installed).📖 Read
via "National Vulnerability Database".
‼ CVE-2022-45363 ‼
📖 Read
via "National Vulnerability Database".
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38649 ‼
📖 Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue affects Apache Airflow Pinot Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Apache Airflow Pinot Provider is installed (Apache Airflow Pinot Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Pinot Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version.📖 Read
via "National Vulnerability Database".
🕴 CybeReady Releases Five Easy Tips to Shop Safely During Black Friday 🕴
📖 Read
via "Dark Reading".
Safe shopping guidance coupled with new CISO tool to help safeguard personal data and corporate networks.📖 Read
via "Dark Reading".
Dark Reading
CybeReady Releases Five Easy Tips to Shop Safely During Black Friday
Safe shopping guidance coupled with new CISO tool to help safeguard personal data and corporate networks.
🕴 Two Estonian Citizens Arrested in $575 Million Cryptocurrency Fraud and Money Laundering Scheme 🕴
📖 Read
via "Dark Reading".
.📖 Read
via "Dark Reading".
Dark Reading
Two Estonian Citizens Arrested in $575 Million Cryptocurrency Fraud and Money Laundering Scheme
.