βΌ CVE-2023-32071 βΌ
π Read
via "National Vulnerability Database".
XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. This has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. The easiest possible workaround is to edit file `<xwiki app>/templates/importinline.vm` and apply the modification described in commit 28905f7f518cc6f21ea61fe37e9e1ed97ef36f01.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31801 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-31240 βΌ
π Read
via "National Vulnerability Database".
An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c file.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30083 βΌ
π Read
via "National Vulnerability Database".
Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the newVar_N in util/decompile.c.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31802 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30084 βΌ
π Read
via "National Vulnerability Database".
An issue found in libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the stackVal function in util/decompile.c.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30086 βΌ
π Read
via "National Vulnerability Database".
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31806 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.π Read
via "National Vulnerability Database".
π΄ ESET APT Report: Attacks by China-, North Korea-, and Iran-aligned Threat Actors; Russia Eyes Ukraine and the EU π΄
π Read
via "Dark Reading".
π Read
via "Dark Reading".
Dark Reading
ESET APT Report: Attacks by China-, North Korea-, and Iran-aligned Threat Actors; Russia Eyes Ukraine and the EU
BRATISLAVA β ESET has released its APT Activity Report, which summarizes the activities of selected advanced persistent threat (APT) groups that were observed, investigated, and analyzed by ESET researchers from October 2022 until the end of March 2023. Theβ¦
βΌ CVE-2022-23818 βΌ
π Read
via "National Vulnerability Database".
Insufficient input validation on the modelspecific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guestmemory integrity.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24948 βΌ
π Read
via "National Vulnerability Database".
Windows Bluetooth Driver Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2021-46749 βΌ
π Read
via "National Vulnerability Database".
Insufficient bounds checking in ASP (AMD SecureProcessor) may allow for an out of bounds read in SMI (System ManagementInterface) mailbox checksum calculation triggering a data abort, resulting in apotential denial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24898 βΌ
π Read
via "National Vulnerability Database".
Windows SMB Denial of Service Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2021-26406 βΌ
π Read
via "National Vulnerability Database".
Insufficient validation in parsing Owner'sCertificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization)and SEV-ES user application can lead to a host crash potentially resulting indenial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24941 βΌ
π Read
via "National Vulnerability Database".
Windows Network File System Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24900 βΌ
π Read
via "National Vulnerability Database".
Windows NTLM Security Support Provider Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24950 βΌ
π Read
via "National Vulnerability Database".
Microsoft SharePoint Server Spoofing Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2021-26354 βΌ
π Read
via "National Vulnerability Database".
Insufficient bounds checking in ASP may allow anattacker to issue a system call from a compromised ABL which may causearbitrary memory values to be initialized to zero, potentially leading to aloss of integrity.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20520 βΌ
π Read
via "National Vulnerability Database".
Improper access control settings in ASPBootloader may allow an attacker to corrupt the return address causing astack-based buffer overrun potentially leading to arbitrary code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46763 βΌ
π Read
via "National Vulnerability Database".
Insufficient input validation in the SMU mayenable a privileged attacker to write beyond the intended bounds of a sharedmemory buffer potentially leading to a loss of integrity.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20524 βΌ
π Read
via "National Vulnerability Database".
An attacker with a compromised ASP couldpossibly send malformed commands to an ASP on another CPU, resulting in an outof bounds write, potentially leading to a loss a loss of integrity.π Read
via "National Vulnerability Database".