โผ CVE-2022-20803 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43929 โผ
๐ Read
via "National Vulnerability Database".
IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-Force ID: 241676.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-36775 โผ
๐ Read
via "National Vulnerability Database".
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 233576.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33926 โผ
๐ Read
via "National Vulnerability Database".
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-34182 โผ
๐ Read
via "National Vulnerability Database".
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-35261 โผ
๐ Read
via "National Vulnerability Database".
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-22868 โผ
๐ Read
via "National Vulnerability Database".
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 244117.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0895 โผ
๐ Read
via "National Vulnerability Database".
The WP Coder รขโฌโ add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the รขโฌหidรขโฌโข parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33226 โผ
๐ Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-40232 โผ
๐ Read
via "National Vulnerability Database".
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should not have access to due to improper permission controls. IBM X-Force ID: 235597.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33237 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting vulnerability in YMFE yapo v1.9.1 allows attacker to execute arbitrary code via the remark parameter of the interface edit page.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26020 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-32142 โผ
๐ Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33391 โผ
๐ Read
via "National Vulnerability Database".
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-32163 โผ
๐ Read
via "National Vulnerability Database".
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33983 โผ
๐ Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the error_ref_sym function.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33949 โผ
๐ Read
via "National Vulnerability Database".
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24785 โผ
๐ Read
via "National Vulnerability Database".
An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-32419 โผ
๐ Read
via "National Vulnerability Database".
An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33950 โผ
๐ Read
via "National Vulnerability Database".
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.๐ Read
via "National Vulnerability Database".
๐ด Not Stoked: Burton Snowboards' Online Orders Disrupted After Cyberattack ๐ด
๐ Read
via "Dark Reading".
The snow sports specialist is investigating to see what caused the operations-disrupting "cyber incident."๐ Read
via "Dark Reading".
Dark Reading
Not Stoked: Burton Snowboards' Online Orders Disrupted After Cyberattack
The snow sports specialist is investigating to see what caused the operations-disrupting "cyber incident."