Skip to content

トピトピニュース

Header Image
Category

HIGH

381 Posts

Featured

Posted byGitHub
[phpxmlrpc/phpxmlrpc] code injection in phpxmlrpc/phpxmlrpc
Posted byGitHub
[ghost] ghost vulnerable to unauthorized newsletter modification via improper access controls
Posted byGitHub
[microweber/microweber] Account Takeover Through Password Reset Poisoning
Posted byGitHub
[apache-airflow] OS Command Injection in Apache Airflow

[muhammara] muhammara and hummus vulnerable to null pointer dereference on bad response object

  • Posted inHIGH
  • Posted byGitHub
  • 11/01/202211/03/2022

The package muhammara before 2.6.0 and the package hummus before 1.0.111 are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-25885
https://github.com/gal…

[muhammara] muhammara and hummus vulnerable to denial of service by NULL pointer dereference

  • Posted inHIGH
  • Posted byGitHub
  • 11/01/202211/03/2022

Impact
The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
Patches
It has been patched in 3.1.1 and ha…

[github.com/cloudflare/cfrpki/cmd/octorpki] OctoRPKI crashes when max iterations is reached

  • Posted inHIGH
  • Posted byGitHub
  • 11/01/202211/01/2022

Impact
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter that would cause the program to crash and not finish the validation and thus a denial of service.
Patches
This issue is fixed in v1.4.4
Wo…

[conduit-hyper] conduit-hyper vulnerable to Denial of Service from unchecked request length

  • Posted inHIGH
  • Posted byGitHub
  • 11/01/202211/03/2022

Prior to version 0.4.2, conduit-hyper did not check any limit on a request’s length before calling hyper::body::to_bytes. An attacker could send a malicious request with an abnormally large Content-Length, which could lead to a panic if memory allocati…

[wintercms/winter] Prototype pollution in Snowboard framework

  • Posted inHIGH
  • Posted byGitHub
  • 10/28/202210/28/2022

Impact
The Snowboard framework in affected versions is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader.
Patches
This issue has been patched in https://github.com/wintercms/winter/commit/2a13faf99972e84c966125…

[jupyter-core] Execution with Unnecessary Privileges in JupyterApp

  • Posted inHIGH
  • Posted byGitHub
  • 10/27/202211/09/2022

Impact
What kind of vulnerability is it? Who is impacted?
We’d like to disclose an arbitrary code execution vulnerability in jupyter_core that stems from jupyter_core executing untrusted files in the current working directory. This vulnerability allows…

[apache-iotdb] Apache IoTDB subject to ReDOS with Java 8

  • Posted inHIGH
  • Posted byGitHub
  • 10/27/202211/09/2022

Apache IoTDB versions 0.12.2 through 0.12.6, and 0.13.0 through 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. This issue is patched in 0.13.3. Users should upgrade or use a later v…

[org.apache.linkis:linkis] Apache Linkis subject to Remote Code Execution via deserialization

  • Posted inHIGH
  • Posted byGitHub
  • 10/27/202211/01/2022

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and ma…

[shescape] Inefficient Regular Expression Complexity in shescape

  • Posted inHIGH
  • Posted byGitHub
  • 10/26/202211/01/2022

Impact
This impacts users that use shescape to escape arguments:

for the Unix shell Bash, or any not-officially-supported Unix shell;
using the escape or escapeAll functions with the interpolation option set to true.

An attacker can cause polynomial …

[azure-cli] Improper Control of Generation of Code (‘Code Injection’) in Azure CLI

  • Posted inHIGH
  • Posted byGitHub
  • 10/26/202210/26/2022

Description
In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source.
For …

Posts navigation

Previous Posts 1 … 4 5 6 7 8 … 39 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close