🚨 CVE-2022-3267
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
🎖@cveNotify
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
🎖@cveNotify
🚨 CVE-2022-37395
A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS attacks.Affected product versions include:CV81-WDM FW versions 01.70.49.29.46.
🎖@cveNotify
A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS attacks.Affected product versions include:CV81-WDM FW versions 01.70.49.29.46.
🎖@cveNotify
huawei
Security Advisory - The input verification vulnerability of a Huawei Device product is involved.
🚨 CVE-2022-33735
There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking to obtain passwords, which may cause sensitive system information to be disclosed.
🎖@cveNotify
There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking to obtain passwords, which may cause sensitive system information to be disclosed.
🎖@cveNotify
huawei
huawei-sa-20220628-01-2eda0853-en
🚨 CVE-2021-46834
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).
🎖@cveNotify
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).
🎖@cveNotify
huawei
huawei-sa-20220819-01-7e0a6103-en
🚨 CVE-2022-34746
An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability could allow an unauthenticated attacker to retrieve a private key by factoring the RSA modulus N in the certificate of the web administration interface.
🎖@cveNotify
An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability could allow an unauthenticated attacker to retrieve a private key by factoring the RSA modulus N in the certificate of the web administration interface.
🎖@cveNotify
🚨 CVE-2022-38619
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
🎖@cveNotify
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
🎖@cveNotify
dtro.gitbook.io
SQL Injection in Terminal MCC Group feature of SmartVista SVFE2 version 2.2.22 (CVE-2022-38619) | Note_CVE
🚨 CVE-2022-35090
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.
🎖@cveNotify
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.
🎖@cveNotify
GitHub
Poc/CVE-2022-35090.md at main · Cvjark/Poc
记录自己使用 fuzz 发现的漏洞,包括产品 version、reproduce 步骤、威胁 rank。也自觉发现这些 POC 并不是重点,可能往后有进一步分析的必要,因此在此记录。 - Poc/CVE-2022-35090.md at main · Cvjark/Poc
🚨 CVE-2022-35089
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.
🎖@cveNotify
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.
🎖@cveNotify
GitHub
Poc/CVE-2022-35089.md at main · Cvjark/Poc
记录自己使用 fuzz 发现的漏洞,包括产品 version、reproduce 步骤、威胁 rank。也自觉发现这些 POC 并不是重点,可能往后有进一步分析的必要,因此在此记录。 - Poc/CVE-2022-35089.md at main · Cvjark/Poc
🚨 CVE-2022-35087
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.
🎖@cveNotify
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.
🎖@cveNotify
GitHub
Poc/CVE-2022-35087.md at main · Cvjark/Poc
记录自己使用 fuzz 发现的漏洞,包括产品 version、reproduce 步骤、威胁 rank。也自觉发现这些 POC 并不是重点,可能往后有进一步分析的必要,因此在此记录。 - Poc/CVE-2022-35087.md at main · Cvjark/Poc
🚨 CVE-2022-35086
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
🎖@cveNotify
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
🎖@cveNotify
GitHub
Poc/CVE-2022-35086.md at main · Cvjark/Poc
记录自己使用 fuzz 发现的漏洞,包括产品 version、reproduce 步骤、威胁 rank。也自觉发现这些 POC 并不是重点,可能往后有进一步分析的必要,因此在此记录。 - Poc/CVE-2022-35086.md at main · Cvjark/Poc
🚨 CVE-2022-35085
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
🎖@cveNotify
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
🎖@cveNotify
🚨 CVE-2022-41231
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.
🎖@cveNotify
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.
🎖@cveNotify
Jenkins Security Advisory 2022-09-21
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-41230
Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.
🎖@cveNotify
Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.
🎖@cveNotify
Jenkins Security Advisory 2022-09-21
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-41229
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
🎖@cveNotify
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
🎖@cveNotify
Jenkins Security Advisory 2022-09-21
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-41228
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.
🎖@cveNotify
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.
🎖@cveNotify
Jenkins Security Advisory 2022-09-21
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-41227
A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.
🎖@cveNotify
A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.
🎖@cveNotify
Jenkins Security Advisory 2022-09-21
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2021-31002
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.0.1, macOS Big Sur 11.6.2. A malicious application may be able to execute arbitrary code with system privileges.
🎖@cveNotify
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.0.1, macOS Big Sur 11.6.2. A malicious application may be able to execute arbitrary code with system privileges.
🎖@cveNotify
Apple Support
About the security content of macOS Monterey 12.0.1
This document describes the security content of macOS Monterey 12.0.1.
🚨 CVE-2022-41138
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
🎖@cveNotify
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
🎖@cveNotify
🚨 CVE-2022-41226
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
🎖@cveNotify
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
🎖@cveNotify
Jenkins Security Advisory 2022-09-21
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-40146
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
🎖@cveNotify
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
🎖@cveNotify