‼ CVE-2022-46424 ‼
📖 Read
via "National Vulnerability Database".
An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v0.4.1.1 and earlier.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23537 ‼
📖 Read
via "National Vulnerability Database".
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown attribute. The vulnerability affects applications that uses STUN including PJNATH and PJSUA-LIB. The patch is available as a commit in the master branch (2.13.1).📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46912 ‼
📖 Read
via "National Vulnerability Database".
An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46771 ‼
📖 Read
via "National Vulnerability Database".
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 242273.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46430 ‼
📖 Read
via "National Vulnerability Database".
TP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46434 ‼
📖 Read
via "National Vulnerability Database".
An issue in the firmware update process of TP-Link TL-WA7510N v1 v3.12.6 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46432 ‼
📖 Read
via "National Vulnerability Database".
An exploitable firmware modification vulnerability was discovered on TP-Link TL-WR743ND V1. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v3.12.20 and earlier.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38873 ‼
📖 Read
via "National Vulnerability Database".
D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta and earlier, DAP-3662 v1.05rc047 and earlier allows attackers to cause a Denial of Service (DoS) via uploading a crafted firmware after modifying the firmware header.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46422 ‼
📖 Read
via "National Vulnerability Database".
An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46914 ‼
📖 Read
via "National Vulnerability Database".
An issue in the firmware update process of TP-LINK TL-WA801N / TL-WA801ND V1 v3.12.16 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46139 ‼
📖 Read
via "National Vulnerability Database".
TP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4515 ‼
📖 Read
via "National Vulnerability Database".
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46423 ‼
📖 Read
via "National Vulnerability Database".
An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v1.2.3.7 and earlier.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46910 ‼
📖 Read
via "National Vulnerability Database".
An issue in the firmware update process of TP-Link TL-WA901ND V1 up to v3.11.2 and TL-WA901N V2 up to v3.12.16 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-43872 ‼
📖 Read
via "National Vulnerability Database".
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46428 ‼
📖 Read
via "National Vulnerability Database".
TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4579 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-39304 ‼
📖 Read
via "National Vulnerability Database".
ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46435 ‼
📖 Read
via "National Vulnerability Database".
An issue in the firmware update process of TP-Link TL-WR941ND V2/V3 up to 3.13.9 and TL-WR941ND V4 up to 3.12.8 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.📖 Read
via "National Vulnerability Database".
🕴 Microsoft Warns on 'Achilles' macOS Gatekeeper Bypass 🕴
📖 Read
via "Dark Reading".
The latest bypass for Apple's application-safety feature could allow malicious takeover of Macs.📖 Read
via "Dark Reading".
Dark Reading
Microsoft Warns on 'Achilles' macOS Gatekeeper Bypass
The latest bypass for Apple's application-safety feature could allow malicious takeover of Macs.
👍1
🕴 Bfore.Ai Releases 'The King, The Knight & The Snowball' - Cybersecurity Book for Children 🕴
📖 Read
via "Dark Reading".
This unique fairytale is available for free just before Christmas to enjoy with the entire family.📖 Read
via "Dark Reading".
Dark Reading
Bfore.Ai Releases 'The King, The Knight & The Snowball' - Cybersecurity Book for Children
This unique fairytale is available for free just before Christmas to enjoy with the entire family.