π¨ CVE-2021-45942
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
π@cveNotify
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
π@cveNotify
π¨ CVE-2022-22828
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
π@cveNotify
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
π@cveNotify
Synametrics
Version History for SynaMan
Trusted by Fortune 500 Companies for cutting edge software products for - Universal Database Querying, Private Cloud Backup, Encrypted File Sharing and Email Security
π¨ CVE-2022-0387
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
π¨ CVE-2022-0370
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
GitHub
CSRF For personal theme Β· LiveHelperChat/livehelperchat@9f5bc33
Live Helper Chat - live support for your website. Featuring web and mobile apps, Voice & Video & ScreenShare. Supports Telegram, Twilio (whatsapp), Facebook messenger including building a bot. - CSRF For personal theme Β· LiveHelperChat/livehelperchat@9f5bc33
π¨ CVE-2022-0372
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
π@cveNotify
huntr.dev
Cross-site Scripting (XSS) - Stored in crater
4.51K developers have been protected by securing crater. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
π¨ CVE-2021-3641
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender GravityZone version 7.1.2.33 and prior versions.
π@cveNotify
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender GravityZone version 7.1.2.33 and prior versions.
π@cveNotify
π¨ CVE-2021-23138
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.
π@cveNotify
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.
π@cveNotify
www.cisa.gov
WECON LeviStudioU | CISA
1. EXECUTIVE SUMMARY
CVSS v3 7.8
ATTENTION: Low attack complexity
Vendor: WECON
Equipment: LeviStudioU
Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow
2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allowβ¦
CVSS v3 7.8
ATTENTION: Low attack complexity
Vendor: WECON
Equipment: LeviStudioU
Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow
2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allowβ¦
π¨ CVE-2021-23157
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.
π@cveNotify
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.
π@cveNotify
www.cisa.gov
WECON LeviStudioU | CISA
1. EXECUTIVE SUMMARY
CVSS v3 7.8
ATTENTION: Low attack complexity
Vendor: WECON
Equipment: LeviStudioU
Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow
2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allowβ¦
CVSS v3 7.8
ATTENTION: Low attack complexity
Vendor: WECON
Equipment: LeviStudioU
Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow
2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allowβ¦
π¨ CVE-2022-21722
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.
π@cveNotify
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.
π@cveNotify
GitHub
Potential out-of-bound read during RTP/RTCP parsing
There are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access.
### Impact
It affects all users that use PJMEDIA and accepts ...
### Impact
It affects all users that use PJMEDIA and accepts ...
π¨ CVE-2021-41166
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.
π@cveNotify
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.
π@cveNotify
GitHub
Merge pull request from GHSA-wff9-w6wc-h67g Β· nextcloud/android@aa47197
Fix GHSL-2021-1008 by using permission instead of readPermission
π¨ CVE-2022-0372
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
π@cveNotify
huntr.dev
Cross-site Scripting (XSS) - Stored in crater
4.51K developers have been protected by securing crater. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
π¨ CVE-2022-22828
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
π@cveNotify
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
π@cveNotify
Synametrics
Version History for SynaMan
Trusted by Fortune 500 Companies for cutting edge software products for - Universal Database Querying, Private Cloud Backup, Encrypted File Sharing and Email Security
π¨ CVE-2022-0387
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
π¨ CVE-2022-0370
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
GitHub
CSRF For personal theme Β· LiveHelperChat/livehelperchat@9f5bc33
Live Helper Chat - live support for your website. Featuring web and mobile apps, Voice & Video & ScreenShare. Supports Telegram, Twilio (whatsapp), Facebook messenger including building a bot. - CSRF For personal theme Β· LiveHelperChat/livehelperchat@9f5bc33
π¨ CVE-2021-46480
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiEval.c:464 in jsiValueObjDelete Β· Issue #61 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case var ar...
π¨ CVE-2021-46478
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiEval.c:120 in jsiClearStack Β· Issue #60 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case var a ...
π¨ CVE-2021-46483
Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiBool.c:17 in BooleanConstructor Β· Issue #62 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case functi...
π¨ CVE-2021-46482
Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiNumber.c:93 in NumberConstructor Β· Issue #66 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case var a ...
π¨ CVE-2021-41550
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
π@cveNotify
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
π@cveNotify
π¨ CVE-2021-41551
Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
π@cveNotify
Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
π@cveNotify
π¨ CVE-2021-4172
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
π@cveNotify
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
π@cveNotify