๐จ CVE-2022-25585
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
๐@cveNotify
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
๐@cveNotify
GitHub
Stored XSS exists ยท Issue #5 ยท union-home/unioncms
1.The problem is in system settings - basic settings - default settings - third party code write๏ผ<script>alert(1)</script> Save, open the home page and the XSS code will pop up The prob...
๐จ CVE-2022-2246
Prototype Pollution in GitHub repository clever/underscore.deep prior to 0.5.3.
๐@cveNotify
Prototype Pollution in GitHub repository clever/underscore.deep prior to 0.5.3.
๐@cveNotify
GitHub
Merge pull request from GHSA-8j79-hfj5-f2xm ยท Clever/underscore.deep@b5e109a
0.5.3
๐จ CVE-2022-2231
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.,2.
๐@cveNotify
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.,2.
๐@cveNotify
huntr.dev
NULL Pointer Dereference in vim
24.63K developers have been protected by securing vim. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
๐จ CVE-2021-3435
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh
๐@cveNotify
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh
๐@cveNotify
GitHub
L2CAP: Information leakage in le_ecred_conn_req()
### Impact
L2CAP: Information leakage in le_ecred_conn_req()
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information
If yo...
L2CAP: Information leakage in le_ecred_conn_req()
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information
If yo...
๐จ CVE-2021-3434
Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6rfp-cfrm
๐@cveNotify
Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6rfp-cfrm
๐@cveNotify
GitHub
L2CAP: Stack based buffer overflow in le_ecred_conn_req()
### Impact
L2CAP: Stack based buffer overflow in le_ecred_conn_req
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information ...
L2CAP: Stack based buffer overflow in le_ecred_conn_req
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information ...
๐จ CVE-2021-3433
Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrp
๐@cveNotify
Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrp
๐@cveNotify
GitHub
BT: Invalid channel map in CONNECT_IND results to Deadlock
### Impact
BT: Invalid channel map in CONNECT_IND results to Deadlock
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have ...
BT: Invalid channel map in CONNECT_IND results to Deadlock
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have ...
๐จ CVE-2021-3431
Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7548-5m6f-mqv9
๐@cveNotify
Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7548-5m6f-mqv9
๐@cveNotify
GitHub
BT: Assertion failure on repeated LL_FEATURE_REQ
### Impact
BT: Assertion failure on repeated LL_FEATURE_REQ
### Patches
This has been fixed in:
- main #33340
- v2.5: #33369
- v1.14: NA
### For more information
If you have any questio...
BT: Assertion failure on repeated LL_FEATURE_REQ
### Patches
This has been fixed in:
- main #33340
- v2.5: #33369
- v1.14: NA
### For more information
If you have any questio...
๐จ CVE-2021-3430
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr
๐@cveNotify
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr
๐@cveNotify
GitHub
BT: Assertion failure on repeated LL_CONNECTION_PARAM_REQ
### Impact
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ.
### Patches
This has been fixed in:
- main: #33272
- v2.5: #33369
- v1.14: #33759
### For more information
If you h...
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ.
### Patches
This has been fixed in:
- main: #33272
- v2.5: #33369
- v1.14: #33759
### For more information
If you h...
๐จ CVE-2021-3432
Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4
๐@cveNotify
Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4
๐@cveNotify
GitHub
BT: Invalid interval in CONNECT_IND leads to Division by Zero
### Impact
Invalid interval in CONNECT_IND leads to Division by Zero
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have a...
Invalid interval in CONNECT_IND leads to Division by Zero
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have a...
๐จ CVE-2022-32974
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
๐@cveNotify
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
๐@cveNotify
Tenableยฎ
[R3] Nessus Version 10.2.0 Fixes Multiple Vulnerabilities
Nessus leverages third-party software to help provide underlying functionality. Several of the third-party components (zlib, expat, jQuery UI) were found to contain vulnerabilities, and updated versions have been made available by the providers. Additionallyโฆ
๐จ CVE-2022-33995
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
๐@cveNotify
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
๐@cveNotify
Devolutions
Devolutions | Productivity & security solutions for IT professionals
Discover one Devolutions ecosystem for remote connections, passwords, privileged access, and automation โ secure productivity for IT professionals worldwide.
๐จ CVE-2022-31884
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
๐@cveNotify
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
๐@cveNotify
Marval
Marval ITSM: Where people, process, and technology unite
Transform your IT and service support operations with Marval ITSM. Our integrated solutions, aligned with ITIL and ISO/IEC 20000, deliver cost reduction, standardization, ICT efficiency, and improved customer satisfaction. Partner with us to elevate yourโฆ
๐จ CVE-2022-25238
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
๐@cveNotify
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
๐@cveNotify
๐จ CVE-2022-24444
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
๐@cveNotify
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
๐@cveNotify
๐จ CVE-2021-41559
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
๐@cveNotify
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
๐@cveNotify
www.silverstripe.org
Security Releases
When potential security holes are discovered in SilverStripe's supported modules[https://docs.silverstripe.org/en/project_governance/supported_modules/], we produce security releases to ensure that you are able to promptly secure your SilverStripe websitesโฆ
๐จ CVE-2020-19897
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
๐@cveNotify
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
๐@cveNotify
GitHub
wuzhicms v4.1.0 statcode reflected xss vulnerability ยท Issue #183 ยท wuzhicms/wuzhicms
A xss vulnerability was discovered in WUZHI CMS 4.1.0 There is a reflected XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of /index....
๐จ CVE-2020-19896
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
๐@cveNotify
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
๐@cveNotify
GitHub
file inclusion vulnerability ยท Issue #36 ยท bg5sbk/MiniCMS
Require: PHP Version <5.3.4 magic_quotes_gpc=off 1. require $index_file $index_file = '../mc-files/posts/index/'.$post_old_state.'.php' $post_old_state = $data['state'] 2...
๐จ CVE-2017-12562
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
๐@cveNotify
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
๐@cveNotify
GitHub
Heap buffer overflows in `psf_binheader_writef` in 1.0.28 and later ยท Issue #292 ยท libsndfile/libsndfile
Case 's' only enlarges the buffer by 16 bytes instead of size bytes. This issue had originally reported by funute against openmpt123 (see https://bugs.openmpt.org/view.php?id=974 )....
๐จ CVE-2021-4156
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
๐@cveNotify
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
๐@cveNotify
๐จ CVE-2022-32532
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
๐@cveNotify
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
๐@cveNotify