🚨 CVE-2023-32039
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
🎖@cveNotify
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
🎖@cveNotify
🚨 CVE-2023-37463
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
🎖@cveNotify
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
🎖@cveNotify
GitHub
Quadratic complexity bugs may lead to a denial of service
### Impact
Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service.
### Proof of concept
Issue 1:
```bash
python...
Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service.
### Proof of concept
Issue 1:
```bash
python...
🚨 CVE-2023-30565
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
🎖@cveNotify
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
🎖@cveNotify
🚨 CVE-2023-30564
Alaris Systems Manager does not perform input validation during the Device Import Function.
🎖@cveNotify
Alaris Systems Manager does not perform input validation during the Device Import Function.
🎖@cveNotify
🚨 CVE-2023-30563
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
🎖@cveNotify
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
🎖@cveNotify
🚨 CVE-2023-30562
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
🎖@cveNotify
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
🎖@cveNotify
🚨 CVE-2023-30561
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
🎖@cveNotify
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
🎖@cveNotify
🚨 CVE-2023-37964
A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
🎖@cveNotify
A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
🎖@cveNotify
Jenkins Security Advisory 2023-07-12
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2023-37963
A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system.
🎖@cveNotify
A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system.
🎖@cveNotify
Jenkins Security Advisory 2023-07-12
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2023-37962
A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system.
🎖@cveNotify
A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system.
🎖@cveNotify
Jenkins Security Advisory 2023-07-12
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software