Skip to content

トピトピニュース

Header Image
Category

HIGH

381 Posts

Featured

Posted byGitHub
[phpxmlrpc/phpxmlrpc] code injection in phpxmlrpc/phpxmlrpc
Posted byGitHub
[ghost] ghost vulnerable to unauthorized newsletter modification via improper access controls
Posted byGitHub
[microweber/microweber] Account Takeover Through Password Reset Poisoning
Posted byGitHub
[apache-airflow] OS Command Injection in Apache Airflow

[lief] LIEF vulnerable to heap based buffer overflow via print_binary function

  • Posted inHIGH
  • Posted byGitHub
  • 09/14/202209/21/2022

LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c. Commit 0033b6312fd311b2e45e379c04a83d77c1e58578 contains a patch.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38495
https…

[com.graphql-java:graphql-java] graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources

  • Posted inHIGH
  • Posted byGitHub
  • 09/13/202209/17/2022

graphql-java before 19.0, 18.3, and 17.4 is vulnerable to Denial of Service. An attacker send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0, 18.3, and 17.4.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3773…

[github.com/casdoor/casdoor] Casdoor arbitrary file write vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 09/10/202209/15/2022

Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-38638
https://github.com/casdoor/casdoor/issues/1035
https://g…

[org.apache.james:james-server] Apache James vulnerable to buffering attack

  • Posted inHIGH
  • Posted byGitHub
  • 09/09/202209/15/2022

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not ta…

[rdiffweb] rdiffweb vulnerable to Improper Restriction of Rendered UI Layers or Frames

  • Posted inHIGH
  • Posted byGitHub
  • 09/09/202209/17/2022

rdiffweb prior to 2.4.1 is vulnerable to Improper Restriction of Rendered UI Layers or Frames. This allows attackers to perform clickjacking attacks that can trick victims into performing actions such as entering passwords, liking or deleting posts, an…

[Blink1Control2] Blink1Control2 uses weak password encryption

  • Posted inHIGH
  • Posted byGitHub
  • 09/08/202209/17/2022

The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. Version 2.2.9 fixes the issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-35513
https://github.com/p1ckzi/CVE-2022-35513
https://gith…

[mei2volpiano] MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)

  • Posted inHIGH
  • Posted byGitHub
  • 09/08/202209/17/2022

DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe ‘xml.etree’ library to parse untrusted XML input.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3718…

[francoisjacquet/rosariosis] RosarioSIS before 10.1 vulnerable to Improper Handling of Length Parameter Inconsistency

  • Posted inHIGH
  • Posted byGitHub
  • 09/07/202209/15/2022

RosarioSIS Student Information System prior to version 10.1 is vulnerable to Improper Handling of Length Parameter Inconsistency.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2714
https://github.com/francoisjacquet/rosariosis/commit/4022954c3f…

[barbican] Barbican authorization flaw before v14.0.0

  • Posted inHIGH
  • Posted byGitHub
  • 09/07/202209/15/2022

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the n…

[golang.org/x/crypto/ssh] x/crypto/ssh vulnerable to panic via SSH server

  • Posted inHIGH
  • Posted byGitHub
  • 09/07/202209/17/2022

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-43565
https://groups.google.com/forum/#!forum/golang-announce
http…

Posts navigation

Previous Posts 1 … 19 20 21 22 23 … 39 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close