π¨ CVE-2022-31009
wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when converting an integer value into the corresponding enum value, causing an exception instead of a fallback to a default value. This issue is fixed in [wire-ios](https://github.com/wireapp/wire-ios/commit/caa0e27dbe51f9edfda8c7a9f017d93b8cfddefb) and in Wire for iOS 3.100. There is no workaround available, but users may use other Wire clients (such as the [web app](https://app.wire.com)) to continue using Wire, or upgrade their client.
π@cveNotify
wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when converting an integer value into the corresponding enum value, causing an exception instead of a fallback to a default value. This issue is fixed in [wire-ios](https://github.com/wireapp/wire-ios/commit/caa0e27dbe51f9edfda8c7a9f017d93b8cfddefb) and in Wire for iOS 3.100. There is no workaround available, but users may use other Wire clients (such as the [web app](https://app.wire.com)) to continue using Wire, or upgrade their client.
π@cveNotify
GitHub
chore: remove unnecessary assert SQCORE-1299 (#5660) Β· wireapp/wire-ios@caa0e27
* chore: remove unnecessary assert
* empty
* empty
π¨ CVE-2017-20088
A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
π@cveNotify
A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
π@cveNotify
Vuldb
CVE-2017-20088 | Atahualpa Theme cross-site request forgery
A vulnerability classified as problematic has been found in Atahualpa Theme. This vulnerability is traded as CVE-2017-20088.
π¨ CVE-2022-2182
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
π@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
π@cveNotify
GitHub
patch 8.2.5150: read past the end of the first line with ":0;'{" Β· vim/vim@f7c7c3f
Problem: Read past the end of the first line with ":0;'{".
Solution: When on line zero check the column is valid for line one.
Solution: When on line zero check the column is valid for line one.
π¨ CVE-2022-34299
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
π@cveNotify
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
π@cveNotify
GitHub
heap overflow in dwarf_global_formref_b Β· Issue #119 Β· davea42/libdwarf-code
asan output: ================================================================= ==3946410==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x61b000000697 at pc 0x0000005d9f2d bp 0x7fffffff9...
π¨ CVE-2022-34328
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
π@cveNotify
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
π@cveNotify
GitHub
GitHub - jenaye/PMB
Contribute to jenaye/PMB development by creating an account on GitHub.
π¨ CVE-2022-34300
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
π@cveNotify
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
π@cveNotify
GitHub
heap overflow in tinyexr::DecodePixelData Β· Issue #167 Β· syoyo/tinyexr
desc There is a heap based buffer overflow in tinyexr::DecodePixelData before 20220506 that could cause remote code execution depending on the usage of this program. asan output ==2363537==ERROR: A...
π¨ CVE-2021-36773
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
π@cveNotify
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
π@cveNotify
π¨ CVE-2022-34835
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
π@cveNotify
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
π@cveNotify
GitLab
i2c: fix stack buffer overflow vulnerability in i2c md command (8f8c04bf) Β· Commits Β· U-Boot / U-Boot Β· GitLab
When running "i2c md 0 0 80000100", the function do_i2c_md parses the length into an unsigned int variable named length. The value is then moved to a signed variable: int...
π¨ CVE-2022-28327
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
π@cveNotify
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
π@cveNotify
π¨ CVE-2022-24675
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
π@cveNotify
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
π@cveNotify
π¨ CVE-2022-2125
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
π@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
π@cveNotify
π¨ CVE-2022-1720
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
π@cveNotify
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
π@cveNotify
GitHub
patch 8.2.4956: reading past end of line with "gf" in Visual block mode Β· vim/vim@395bd1f
Problem: Reading past end of line with "gf" in Visual block mode.
Solution: Do not include the NUL in the length.
Solution: Do not include the NUL in the length.
π¨ CVE-2017-20125
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
Vuldb
CVE-2017-20125 | Online Hotel Booking System Pro roomtype-details.php sql injection (EDB-41181)
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. This vulnerability is known as CVE-2017-20125.
π¨ CVE-2017-20124
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
Exploit Database
WordPress Plugin Online Hotel Booking System Pro 1.0 - SQL Injection
WordPress Plugin Online Hotel Booking System Pro 1.0 - SQL Injection.. webapps exploit for PHP platform
π¨ CVE-2017-20123
A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this issue. It is recommended to upgrade the affected component.
π@cveNotify
A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this issue. It is recommended to upgrade the affected component.
π@cveNotify
GitHub
exploits/Viscosity at master Β· kacperszurek/exploits
Contribute to kacperszurek/exploits development by creating an account on GitHub.