Skip to content

トピトピニュース

Header Image

[Microsoft.NETCore.App.Runtime.linux-arm64] .NET Core & .NET Framework Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/22/2022

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka ‘.NET Core & .NET Framework Denial of Service Vulnerability’.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-1108
https://portal.m…

[org.apache.dubbo:dubbo-rpc-http-invoker] Deserialization of Untrusted Data in Apache Dubbo

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/05/2022

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This i…

[org.codehaus.mevenide:netbeans] Improper Verification of Cryptographic Signature in Apache Netbeans

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/15/2022

The “Apache NetBeans” autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. “Apache NetBeans” versions up to and including 11.2 are affected by this vulnerability. NetBeans r…

[org.apache.struts:struts2-core] Cross-site Scripting in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/04/2022

When the Struts2 debug mode is turned on, under certain conditions an arbitrary script may be executed in the ‘Problem Report’ screen. Also if JSP files are exposed to be accessed directly it’s possible to execute an arbitrary script.
It is generally …

[io.undertow:undertow-core] Undertow vulnerable to Uncontrolled Resource Consumption

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/08/2022

A vulnerability was found in the Undertow HTTP server in versions before 2.0.29 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
References

https://nvd.nist.g…

[Microsoft.WindowsDesktop.App.Runtime.win-x86] Remote code execution in Microsoft.WindowsDesktop.App.Ref

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/29/2022

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka ‘.NET F…

[Microsoft.AspNetCore.App.Runtime.linux-x64] Denial of service in ASP.NET Core

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202210/29/2022

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka ‘ASP.NET Core Denial of Service Vulnerability’.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-0602
https://access.redhat.com/errata/RHSA-2020:0130
h…

[org.keycloak:keycloak-core] keycloak vulnerable to unauthorized login via mail server setup

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202209/13/2022

A flaw was found in keycloack before version 8.0.0. The owner of ‘placeholder.org’ domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name ‘test’ the email address w…

[org.springframework:spring-web] Spring Framework lacks documentation for unsafe deserialization

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/15/2022

Pivotal Spring Framework 4.1.4 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication …

[com.yahoo.athenz:athenz] Athenz vulnerable to Open Redirect

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/05/2022

Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted page.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-6035
https://git…

Posts navigation

Previous Posts 1 … 86,767 86,768 86,769 86,770 86,771 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close