π¨ CVE-2022-38037
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38038, CVE-2022-38039.
π@cveNotify
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38038, CVE-2022-38039.
π@cveNotify
π¨ CVE-2022-44052
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
PyPI
democritus-timezones
Democritus functions for working with timezones.
π¨ CVE-2022-41669
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
π@cveNotify
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
π@cveNotify
π¨ CVE-2022-41670
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
π@cveNotify
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
π@cveNotify
π¨ CVE-2022-41671
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (βSQL Injectionβ) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
π@cveNotify
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (βSQL Injectionβ) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
π@cveNotify
π¨ CVE-2022-44054
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
PyPI
democritus-utility
Democritus functions for working with utility functions.
π¨ CVE-2022-44051
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
π¨ CVE-2022-44053
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0.
π@cveNotify
PyPI
d8s-networking
Democritus functions for working with network requests.
π¨ CVE-2022-0554
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
π@cveNotify
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
π@cveNotify
GitHub
patch 8.2.4327: may end up with no current buffer Β· vim/vim@e3537ae
Problem: May end up with no current buffer.
Solution: When deleting the current buffer to not pick a quickfix buffer as
the new current buffer.
Solution: When deleting the current buffer to not pick a quickfix buffer as
the new current buffer.
π¨ CVE-2022-0572
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
π@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
π@cveNotify
π¨ CVE-2022-0685
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
π@cveNotify
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
π@cveNotify
π¨ CVE-2022-0714
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
π@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
π@cveNotify
GitHub
patch 8.2.4436: crash with weird 'vartabstop' value Β· vim/vim@4e889f9
Problem: Crash with weird 'vartabstop' value.
Solution: Check for running into the end of the line.
Solution: Check for running into the end of the line.
π¨ CVE-2022-0729
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
π@cveNotify
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
π@cveNotify
huntr.dev
Use of Out-of-range Pointer Offset in vim
24.63K developers have been protected by securing vim. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
π¨ CVE-2022-1154
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
π@cveNotify
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
π@cveNotify
huntr.dev
Use After Free in vim
24.63K developers have been protected by securing vim. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
π¨ CVE-2022-0943
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
π@cveNotify
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
π@cveNotify
GitHub
patch 8.2.4563: "z=" in Visual mode may go beyond the end of the line Β· vim/vim@5c68617
Problem: "z=" in Visual mode may go beyond the end of the line.
Solution: Adjust "badlen".
Solution: Adjust "badlen".
π¨ CVE-2022-1616
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
π@cveNotify
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
π@cveNotify
GitHub
patch 8.2.4895: buffer overflow with invalid command with composing c⦠· vim/vim@d889344
β¦hars
Problem: Buffer overflow with invalid command with composing chars.
Solution: Check that the whole character fits in the buffer.
Problem: Buffer overflow with invalid command with composing chars.
Solution: Check that the whole character fits in the buffer.
π¨ CVE-2022-1720
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
π@cveNotify
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
π@cveNotify
GitHub
patch 8.2.4956: reading past end of line with "gf" in Visual block mode Β· vim/vim@395bd1f
Problem: Reading past end of line with "gf" in Visual block mode.
Solution: Do not include the NUL in the length.
Solution: Do not include the NUL in the length.