‼ CVE-2023-28102 ‼
📖 Read
via "National Vulnerability Database".
discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` file unsafely constructs a shell string using the file parameter, which can potentially leave clients of discordrb vulnerable to command injection. The library is not directly exploitable: the exploit requires that some client of the library calls the vulnerable method with user input. However, if unsafe input reaches the library method, then an attacker can execute arbitrary shell commands on the host machine. Full impact will depend on the permissions of the process running the `discordrb` library and will likely not be total system access. This issue has been addressed in code, but a new release of the `discordrb` gem has not been uploaded to rubygems. This issue is also tracked as `GHSL-2022-094`.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-48347 ‼
📖 Read
via "National Vulnerability Database".
The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-48358 ‼
📖 Read
via "National Vulnerability Database".
The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service exceptions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1665 ‼
📖 Read
via "National Vulnerability Database".
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-48357 ‼
📖 Read
via "National Vulnerability Database".
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40595 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40592 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40587 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40599 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40594 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-48346 ‼
📖 Read
via "National Vulnerability Database".
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-26924 ‼
📖 Read
via "National Vulnerability Database".
LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40586 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40589 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-48352 ‼
📖 Read
via "National Vulnerability Database".
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40577 ‼
📖 Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.📖 Read
via "National Vulnerability Database".
âš Apple patches everything, including a zero-day fix for iOS 15 users âš
📖 Read
via "Naked Security".
Got an older iPhone that can't run iOS 16? You've got a zero-day to deal with! That super-cool Studio Display monitor needs patching, too.📖 Read
via "Naked Security".
Sophos News
Naked Security – Sophos News
🕴 How CISOs Can Reduce the Danger of Using Data Brokers 🕴
📖 Read
via "Dark Reading".
Without proof that it was collected legally, purchased data can threaten an enterprise's security compliance and may expose the company to litigation.📖 Read
via "Dark Reading".
Dark Reading
How CISOs Can Reduce the Danger of Using Data Brokers
Without proof that it was collected legally, purchased data can threaten an enterprise's security compliance and even expose the company to litigation.
‼ CVE-2022-45825 ‼
📖 Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-46855 ‼
📖 Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.6 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25704 ‼
📖 Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions.📖 Read
via "National Vulnerability Database".