๐จ CVE-2022-41220
** DISPUTED ** md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input.
๐@cveNotify
** DISPUTED ** md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input.
๐@cveNotify
๐จ CVE-2022-41218
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
๐@cveNotify
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
๐@cveNotify
๐จ CVE-2022-3080
By sending specific queries to the resolver, an attacker can cause named to crash.
๐@cveNotify
By sending specific queries to the resolver, an attacker can cause named to crash.
๐@cveNotify
kb.isc.org
CVE-2022-3080: BIND 9 resolvers configured to answer from stale cache
๐จ CVE-2022-38178
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
๐@cveNotify
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
๐@cveNotify
kb.isc.org
CVE-2022-38178: Memory leaks in EdDSA DNSSEC verification code
๐จ CVE-2022-38177
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
๐@cveNotify
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
๐@cveNotify
kb.isc.org
CVE-2022-38177: Memory leak in ECDSA DNSSEC verification code
๐จ CVE-2022-2906
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
๐@cveNotify
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
๐@cveNotify
kb.isc.org
CVE-2022-2906 Memory Leak in DH Code
๐จ CVE-2022-2881
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
๐@cveNotify
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
๐@cveNotify
kb.isc.org
CVE-2022-2881: Buffer overread in statistics channel code
๐จ CVE-2022-2795
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
๐@cveNotify
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
๐@cveNotify
kb.isc.org
CVE-2022-2795: Processing large delegations may severely degrade resolver performance
๐จ CVE-2022-2872
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
๐@cveNotify
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
๐@cveNotify
GitHub
๐๏ธ Enforce valid type on copy/move of uploads ยท OctoPrint/OctoPrint@3e3c118
Also enforce that on downloads and mirror it on the
API.
Prevents accidental or intentional renaming of
valid files to something like .html to e.g. attempt
to run arbitrary JS code in the browser ...
API.
Prevents accidental or intentional renaming of
valid files to something like .html to e.g. attempt
to run arbitrary JS code in the browser ...
๐จ CVE-2022-39003
Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components.
๐@cveNotify
Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components.
๐@cveNotify
๐จ CVE-2022-39004
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
๐@cveNotify
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
๐@cveNotify
Harmonyos
September-2022-Huawei Phone/Tablet Security Bulletins-Updates-HarmonyOSDevice
September
HarmonyOS Security Bulletins for Huawei Phones and Tablets - Sepโฆโฆ
HarmonyOS Security Bulletins for Huawei Phones and Tablets - Sepโฆโฆ
๐จ CVE-2022-39005
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
๐@cveNotify
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
๐@cveNotify
Harmonyos
September-2022-Huawei Phone/Tablet Security Bulletins-Updates-HarmonyOSDevice
September
HarmonyOS Security Bulletins for Huawei Phones and Tablets - Sepโฆโฆ
HarmonyOS Security Bulletins for Huawei Phones and Tablets - Sepโฆโฆ
๐จ CVE-2022-25873
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
๐@cveNotify
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
๐@cveNotify
Learn more about Maven with Snyk Open Source Vulnerability Database
Cross-site Scripting (XSS) in org.webjars.npm:vuetify | CVE-2022-25873 | Snyk
Medium severity (4.6) Cross-site Scripting (XSS) in org.webjars.npm:vuetify | CVE-2022-25873
๐จ CVE-2022-39006
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
๐@cveNotify
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
๐@cveNotify
Harmonyos
September-2022-Huawei Phone/Tablet Security Bulletins-Updates-HarmonyOSDevice
September
HarmonyOS Security Bulletins for Huawei Phones and Tablets - Sepโฆโฆ
HarmonyOS Security Bulletins for Huawei Phones and Tablets - Sepโฆโฆ
๐จ CVE-2022-3068
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
๐@cveNotify
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
๐@cveNotify
huntr.dev
Improper Privilege Management in octoprint
6.56K developers have been protected by securing octoprint. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
๐จ CVE-2022-2888
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
๐@cveNotify
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
๐@cveNotify
GitHub
๐ Make session handling more secure ยท OctoPrint/OctoPrint@40e6217
* ๐๏ธ Tie remember_me cookie to password hash
That way when the password gets changed,
existing cookies automatically get
invalidated.
* ๐๏ธ Invalidate user sessions on password change
Thi...
That way when the password gets changed,
existing cookies automatically get
invalidated.
* ๐๏ธ Invalidate user sessions on password change
Thi...
๐จ CVE-2022-35699
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe
Adobe Security Bulletin
Security Updates Available for Adobe Bridge | APSB22-49
๐จ CVE-2022-38425
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe
Adobe Security Bulletin
Security Updates Available for Adobe Bridge | APSB22-49
๐จ CVE-2022-35709
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe
Adobe Security Bulletin
Security Updates Available for Adobe Bridge | APSB22-49
๐จ CVE-2022-35708
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
๐@cveNotify
Adobe
Adobe Security Bulletin
Security Updates Available for Adobe Bridge | APSB22-49
๐จ CVE-2022-30767
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
๐@cveNotify
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
๐@cveNotify