Skip to content

トピトピニュース

Header Image
Category

HIGH

381 Posts

Featured

Posted byGitHub
[phpxmlrpc/phpxmlrpc] code injection in phpxmlrpc/phpxmlrpc
Posted byGitHub
[ghost] ghost vulnerable to unauthorized newsletter modification via improper access controls
Posted byGitHub
[microweber/microweber] Account Takeover Through Password Reset Poisoning
Posted byGitHub
[apache-airflow] OS Command Injection in Apache Airflow

[Microsoft.AspNetCore.App.Runtime.linux-arm] ASP.NET Core Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/25/2022

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka ASP.NET Core Denial of Service Vulnerability.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-1597
https://lists.fedoraproject.org/archives/list/packa…

[Microsoft.NETCore.App.Runtime.linux-arm64] .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/22/2022

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka ‘.NET Framework, SharePoint Server, and Visual Studio Remote Code Executio…

[Microsoft.AspNetCore.App.Runtime.linux-musl-x64] ASP.NET Core Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/22/2022

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka ‘ASP.NET Core Denial of Service Vulnerability’.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-1161
https://portal.msrc.microsoft.com/en-US/security-…

[Microsoft.NETCore.App.Runtime.linux-arm64] .NET Core & .NET Framework Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/22/2022

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka ‘.NET Core & .NET Framework Denial of Service Vulnerability’.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-1108
https://portal.m…

[org.codehaus.mevenide:netbeans] Improper Verification of Cryptographic Signature in Apache Netbeans

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/15/2022

The “Apache NetBeans” autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. “Apache NetBeans” versions up to and including 11.2 are affected by this vulnerability. NetBeans r…

[io.undertow:undertow-core] Undertow vulnerable to Uncontrolled Resource Consumption

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/08/2022

A vulnerability was found in the Undertow HTTP server in versions before 2.0.29 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
References

https://nvd.nist.g…

[Microsoft.WindowsDesktop.App.Runtime.win-x86] Remote code execution in Microsoft.WindowsDesktop.App.Ref

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/29/2022

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka ‘.NET F…

[io.alauda.jenkins.plugins:alauda-kubernetes-support] Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/04/2022

A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kub…

[com.inflectra.spiratest.plugins:inflectra-spira-integration] Improper Certificate Validation in Jenkins Spira Importer Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/02/2022

Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-16558
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1580
http://www.op…

[pyarrow] Missing Initialization of Resource in Apache Arrow

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202211/10/2022

It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to uninitialized m…

Posts navigation

Previous Posts 1 … 26 27 28 29 30 … 39 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close