π¨ CVE-2021-23157
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.
π@cveNotify
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.
π@cveNotify
www.cisa.gov
WECON LeviStudioU | CISA
1. EXECUTIVE SUMMARY
CVSS v3 7.8
ATTENTION: Low attack complexity
Vendor: WECON
Equipment: LeviStudioU
Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow
2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allowβ¦
CVSS v3 7.8
ATTENTION: Low attack complexity
Vendor: WECON
Equipment: LeviStudioU
Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow
2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allowβ¦
π¨ CVE-2022-21722
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.
π@cveNotify
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.
π@cveNotify
GitHub
Potential out-of-bound read during RTP/RTCP parsing
There are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access.
### Impact
It affects all users that use PJMEDIA and accepts ...
### Impact
It affects all users that use PJMEDIA and accepts ...
π¨ CVE-2021-41166
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.
π@cveNotify
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.
π@cveNotify
GitHub
Merge pull request from GHSA-wff9-w6wc-h67g Β· nextcloud/android@aa47197
Fix GHSL-2021-1008 by using permission instead of readPermission
π¨ CVE-2022-0372
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
π@cveNotify
huntr.dev
Cross-site Scripting (XSS) - Stored in crater
4.51K developers have been protected by securing crater. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
π¨ CVE-2022-22828
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
π@cveNotify
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
π@cveNotify
Synametrics
Version History for SynaMan
Trusted by Fortune 500 Companies for cutting edge software products for - Universal Database Querying, Private Cloud Backup, Encrypted File Sharing and Email Security
π¨ CVE-2022-0387
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
π¨ CVE-2022-0370
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
π@cveNotify
GitHub
CSRF For personal theme Β· LiveHelperChat/livehelperchat@9f5bc33
Live Helper Chat - live support for your website. Featuring web and mobile apps, Voice & Video & ScreenShare. Supports Telegram, Twilio (whatsapp), Facebook messenger including building a bot. - CSRF For personal theme Β· LiveHelperChat/livehelperchat@9f5bc33
π¨ CVE-2021-46480
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiEval.c:464 in jsiValueObjDelete Β· Issue #61 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case var ar...
π¨ CVE-2021-46478
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiEval.c:120 in jsiClearStack Β· Issue #60 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case var a ...
π¨ CVE-2021-46483
Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiBool.c:17 in BooleanConstructor Β· Issue #62 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case functi...
π¨ CVE-2021-46482
Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
π@cveNotify
Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
π@cveNotify
GitHub
Heap-buffer-overflow src/jsiNumber.c:93 in NumberConstructor Β· Issue #66 Β· pcmacdon/jsish
Jsish revision Commit: 9fa798e Version: v3.5.0 Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps export CFLAGS='-fsanitize=address' make Test case var a ...
π¨ CVE-2021-41550
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
π@cveNotify
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
π@cveNotify
π¨ CVE-2021-41551
Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
π@cveNotify
Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
π@cveNotify
π¨ CVE-2021-4172
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
π@cveNotify
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
π@cveNotify
π¨ CVE-2021-4103
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.
π@cveNotify
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.
π@cveNotify
GitHub
:lock: SVG δΊδ»Άε―Όθ΄η XSS ζΌζ΄ Fix https://github.com/Vanessa219/vditor/issuβ¦ Β· Vanessa219/vditor@8d4d088
β¦es/1133
π¨ CVE-2022-23120
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.
π@cveNotify
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.
π@cveNotify
π¨ CVE-2022-23305
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
π@cveNotify
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
π@cveNotify
π¨ CVE-2022-23119
A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.
π@cveNotify
A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.
π@cveNotify
π¨ CVE-2021-45380
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
π@cveNotify
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
π@cveNotify
GitHub
XSS injection vulnerability exists in \templates\m\inc_head.php Β· Issue #8 Β· source-trace/appcms
inc_head.php <input type="text" id="abc" class="search-txt" value="<?php if(isset($_GET['q'])) echo $_GE...
π¨ CVE-2021-46024
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
π@cveNotify
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
π@cveNotify
GitHub
SQL Injection vulnerability via the "id" parameter in cart_add.php Β· Issue #3 Β· projectworldsofficial/online-shopping-webvsiteβ¦
Version: 1.0 No login is required ' AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT (ELT(1=1,user()))),0x7e)) AND 'a'='a Source code review Remediation Validate input of idpa...
π¨ CVE-2022-23857
model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).
π@cveNotify
model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).
π@cveNotify
GitHub
Release v0.47.5 Β· navidrome/navidrome
This bug-fix release includes a fix to a potential SQL injection and a couple of other niceties and fixes.
There are a few nice contributions that needs more testing, and I plan to validate and rel...
There are a few nice contributions that needs more testing, and I plan to validate and rel...