🚨 CVE-2022-31291
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
🎖@cveNotify
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
🎖@cveNotify
GitHub
dlt_config_file_parser.c:Fix a pointer release bug in the file。 by Leslie-bcy · Pull Request #376 · COVESA/dlt-daemon
In the dlt_config_file_set_section function of dlt_config_file_parser.c, the following code exists:
s-name is not set to null after free.
It will be freed again in the dlt_config_file_release fu...
s-name is not set to null after free.
It will be freed again in the dlt_config_file_release fu...
🚨 CVE-2022-27532
A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.
🎖@cveNotify
A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.
🎖@cveNotify
Autodesk
Security Advisories | Autodesk Trust Center
Autodesk applies cloud-computing security best practices in data center location, operations, facility characteristics, software controls, and risk mitigation.
🚨 CVE-2022-27531
A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
🎖@cveNotify
A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
🎖@cveNotify
Autodesk
Security Advisories | Autodesk Trust Center
Autodesk applies cloud-computing security best practices in data center location, operations, facility characteristics, software controls, and risk mitigation.
🚨 CVE-2022-22953
VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information.
🎖@cveNotify
VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information.
🎖@cveNotify
VMware
VMSA-2022-0017
VMware HCX update address an information disclosure vulnerability (CVE-2022-22953)
🚨 CVE-2021-27786
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
🎖@cveNotify
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
🎖@cveNotify
Hcltechsw
Security Bulletin: HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trusted (CVE-2021-27786)…
HCL OneTest Server has a vulnerablity associated with HTML5 cross-origin resource sharing (CORS) policy
🚨 CVE-2022-24065
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
🎖@cveNotify
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
🎖@cveNotify
Learn more about pip with Snyk Open Source Vulnerability Database
Command Injection in cookiecutter | CVE-2022-24065 | Snyk
High severity (8.1) Command Injection in cookiecutter | CVE-2022-24065
🚨 CVE-2022-29225
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.
🎖@cveNotify
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.
🎖@cveNotify
GitHub
Decompressors can be zip bombed
# Attack type
Remote, dataplane
# Impact
Denial of Service
# Affected component(s)
All decompressor filters
# Attack vector(s)
A specifically constructed HTTP body delivered by an untr...
Remote, dataplane
# Impact
Denial of Service
# Affected component(s)
All decompressor filters
# Attack vector(s)
A specifically constructed HTTP body delivered by an untr...
🚨 CVE-2022-31384
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
🎖@cveNotify
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
🎖@cveNotify
GitHub
POC/CVE-2022-31384.txt at main · laotun-s/POC
Contribute to laotun-s/POC development by creating an account on GitHub.
🚨 CVE-2022-31383
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
🎖@cveNotify
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
🎖@cveNotify
🚨 CVE-2022-30656
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Update Available for Adobe InCopy | APSB22-29
🚨 CVE-2022-30655
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Update Available for Adobe InCopy | APSB22-29
🚨 CVE-2022-30654
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Update Available for Adobe InCopy | APSB22-29
🚨 CVE-2022-30653
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Update Available for Adobe InCopy | APSB22-29
🚨 CVE-2022-30652
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Update Available for Adobe InCopy | APSB22-29
🚨 CVE-2022-30651
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Update Available for Adobe InCopy | APSB22-29
🚨 CVE-2022-30650
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Update Available for Adobe InCopy | APSB22-29
🚨 CVE-2022-2085
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not have an init_device_procs defined. This flaw allows an attacker to parse a large number of bits (more than 64 bits per pixel), which triggers a NULL pointer dereference flaw, causing an application to crash.
🎖@cveNotify
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not have an init_device_procs defined. This flaw allows an attacker to parse a large number of bits (more than 64 bits per pixel), which triggers a NULL pointer dereference flaw, causing an application to crash.
🎖@cveNotify
🚨 CVE-2022-29866
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.
🎖@cveNotify
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.
🎖@cveNotify
OPC Foundation
Security - OPC Foundation
April 14th, 2026 The members of the “Industrial Security Harmonization Group” (ISHG), are pleased to share the Joint Working Group paper “Secure Deployment of Industrial Communication Protocols – A Risk Management Based Approach” Feb 10, 2026: As a contributor…
🚨 CVE-2022-29864
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.
🎖@cveNotify
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.
🎖@cveNotify
OPC Foundation
Security - OPC Foundation
April 14th, 2026 The members of the “Industrial Security Harmonization Group” (ISHG), are pleased to share the Joint Working Group paper “Secure Deployment of Industrial Communication Protocols – A Risk Management Based Approach” Feb 10, 2026: As a contributor…
🚨 CVE-2022-29863
OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.
🎖@cveNotify
OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.
🎖@cveNotify
OPC Foundation
Security - OPC Foundation
April 14th, 2026 The members of the “Industrial Security Harmonization Group” (ISHG), are pleased to share the Joint Working Group paper “Secure Deployment of Industrial Communication Protocols – A Risk Management Based Approach” Feb 10, 2026: As a contributor…
🚨 CVE-2021-41487
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
🎖@cveNotify
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
🎖@cveNotify
Twitter
Exploit Database
[webapps] NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection dlvr.it/RXWP5h