βΌ CVE-2023-26547 βΌ
π Read
via "National Vulnerability Database".
The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1648 βΌ
π Read
via "National Vulnerability Database".
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26548 βΌ
π Read
via "National Vulnerability Database".
The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0210 βΌ
π Read
via "National Vulnerability Database".
A bug affects the Linux kernelΓ’β¬β’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28102 βΌ
π Read
via "National Vulnerability Database".
discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` file unsafely constructs a shell string using the file parameter, which can potentially leave clients of discordrb vulnerable to command injection. The library is not directly exploitable: the exploit requires that some client of the library calls the vulnerable method with user input. However, if unsafe input reaches the library method, then an attacker can execute arbitrary shell commands on the host machine. Full impact will depend on the permissions of the process running the `discordrb` library and will likely not be total system access. This issue has been addressed in code, but a new release of the `discordrb` gem has not been uploaded to rubygems. This issue is also tracked as `GHSL-2022-094`.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48347 βΌ
π Read
via "National Vulnerability Database".
The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48358 βΌ
π Read
via "National Vulnerability Database".
The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service exceptions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1665 βΌ
π Read
via "National Vulnerability Database".
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48357 βΌ
π Read
via "National Vulnerability Database".
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40595 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40592 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40587 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40599 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40594 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48346 βΌ
π Read
via "National Vulnerability Database".
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26924 βΌ
π Read
via "National Vulnerability Database".
LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40586 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40589 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2022-48352 βΌ
π Read
via "National Vulnerability Database".
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40577 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.π Read
via "National Vulnerability Database".
β Apple patches everything, including a zero-day fix for iOS 15 users β
π Read
via "Naked Security".
Got an older iPhone that can't run iOS 16? You've got a zero-day to deal with! That super-cool Studio Display monitor needs patching, too.π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News