๐จ CVE-2021-23236
Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressing a button on the rack system.
๐@cveNotify
Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressing a button on the rack system.
๐@cveNotify
๐จ CVE-2021-46548
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV src/mjs_bcode.c:15 in add_lineno_map_item ยท Issue #228 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46547
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV (/usr/local/bin/mjs+0x2c17e) ยท Issue #221 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46546
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_next at src/mjs_object.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_next at src/mjs_object.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV src/mjs_object.c:255 in mjs_next ยท Issue #213 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46545
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x4b44b. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x4b44b. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV (/lib/x86_64-linux-gnu/libc.so.6+0x4b44b) ยท Issue #218 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46544
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x59e19. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x59e19. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV (/usr/lib/x86_64-linux-gnu/libasan.so.4+0x59e19) ยท Issue #220 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46543
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e810. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e810. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV (/lib/x86_64-linux-gnu/libc.so.6+0x18e810) ยท Issue #219 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46554
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_json_stringify at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_json_stringify at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV src/mjs_json.c:273 in mjs_json_stringify ยท Issue #229 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46553
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_set_internal at src/mjs_object.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_set_internal at src/mjs_object.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV src/mjs_object.c:207 in mjs_set_internal ยท Issue #226 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46550
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via free_json_frame at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via free_json_frame at src/mjs_json.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV src/mjs_json.c:323 in free_json_frame ยท Issue #230 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46549
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV src/mjs_ffi.c:50 in parse_cval_type ยท Issue #224 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46548
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV src/mjs_bcode.c:15 in add_lineno_map_item ยท Issue #228 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2021-46547
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial of Service (DoS).
๐@cveNotify
GitHub
SEGV (/usr/local/bin/mjs+0x2c17e) ยท Issue #221 ยท cesanta/mjs
mJS revision Commit: b1b6eac Build platform Ubuntu 18.04.5 LTS (Linux 5.4.0-44-generic x86_64) Build steps vim Makefile DOCKER_GCC=gcc $(DOCKER_GCC) $(CFLAGS) $(TOP_MJS_SOURCES) $(TOP_COMMON_SOURCE...
๐จ CVE-2022-21719
GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.
๐@cveNotify
GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.
๐@cveNotify
GitHub
GitHub is where people build software. More than 73 million people use GitHub to discover, fork, and contribute to over 200 million projects.
๐จ CVE-2022-24071
A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs.
๐@cveNotify
A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs.
๐@cveNotify
๐จ CVE-2020-28885
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever.
๐@cveNotify
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever.
๐@cveNotify
Medium
Some way to execute OS command in Liferay Portal
Recently, I have a chance to work with Liferay CE Portal and explore some attack vectors to execute OS command on it.
๐จ CVE-2020-28884
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever.
๐@cveNotify
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever.
๐@cveNotify
Medium
Some way to execute OS command in Liferay Portal
Recently, I have a chance to work with Liferay CE Portal and explore some attack vectors to execute OS command on it.
๐จ CVE-2022-21720
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.
๐@cveNotify
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.
๐@cveNotify
GitHub
GitHub is where people build software. More than 73 million people use GitHub to discover, fork, and contribute to over 200 million projects.
๐จ CVE-2022-0394
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
๐@cveNotify
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
๐@cveNotify
GitHub
Escape for angular in embed pages ยท LiveHelperChat/livehelperchat@d7b8546
Live Helper Chat - live support for your website. Featuring web and mobile apps, Voice & Video & ScreenShare. Supports Telegram, Twilio (whatsapp), Facebook messenger including building a bot. - Escape for angular in embed pages ยท LiveHelperChat/livehelperchat@d7b8546
๐จ CVE-2021-42791
An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A user can trigger push notifications for any other user. The text contained in the push notification can also be modified. If a user who receives the notification accepts it, then the user who triggered the notification can obtain the accepting user's login certificate.
๐@cveNotify
An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A user can trigger push notifications for any other user. The text contained in the push notification can also be modified. If a user who receives the notification accepts it, then the user who triggered the notification can obtain the accepting user's login certificate.
๐@cveNotify
Veridium
Veridium Eliminates Passwords with VeridiumAD for Enterprises Using Microsoft Active Directory
VeridiumAD enhances enterprise security and ease of employee login through Active Directory while reducing password reset costs by more than 50 percent.
๐จ CVE-2021-39293
In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.
๐@cveNotify
In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.
๐@cveNotify