Skip to content

トピトピニュース

Header Image
Category

MODERATE

505 Posts

Featured

Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Posted byGitHub
[org.postgresql:postgresql] TemporaryFolder on unix-like systems does not limit access to created files
Posted byGitHub
[com.h2database:h2] Password exposure in H2 Database

[commons-jxpath:commons-jxpath] JXPath Out-of-bounds Write vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/11/2022

Those using JXPath to interpret XPath may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a deni…

[commons-jxpath:commons-jxpath] JXPath Out-of-bounds Write vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/11/2022

Those using JXPath to interpret XPath may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a deni…

[commons-jxpath:commons-jxpath] JXPath Out-of-bounds Write vulnerability

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/20/2022

Those using JXPath to interpret XPath may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a deni…

[yetiforce/yetiforce-crm] YetiForce CRM vulnerable to stored Cross-site Scripting

  • Posted inMODERATE
  • Posted byGitHub
  • 10/07/202210/07/2022

YetiForce CRM version 6.4.0 and prior is vulnerable to stored cross-site scripting. A patch is available on the developer branch.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-3002
https://github.com/yetiforcecompany/yetiforcecrm/commit/54728be…

[google-protobuf] protobuf-java has a potential Denial of Service issue

  • Posted inMODERATE
  • Posted byGitHub
  • 10/05/202210/20/2022

Summary
A potential Denial of Service issue in protobuf-java core and lite was discovered in the parsing procedure for binary and text format data. Input streams containing multiple instances of non-repeated embedded messages with repeated or unknown f…

[label-studio] Heartex – Label Studio Community Edition vulnerable to SSRF in the Data Import module

  • Posted inMODERATE
  • Posted byGitHub
  • 10/04/202210/05/2022

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex – Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by def…

[lief] LIEF vulnerable to denial of service through segmentation fault

  • Posted inMODERATE
  • Posted byGitHub
  • 10/04/202210/07/2022

A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file. A patch for this issue is available at commit fde2c4898…

[OrchardCore] OrchardCore vulnerable to HTML injection

  • Posted inMODERATE
  • Posted byGitHub
  • 10/04/202210/05/2022

OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard th…

[DotNetNuke.Web] DNN vulnerable to Relative Path Traversal

  • Posted inMODERATE
  • Posted byGitHub
  • 10/01/202210/05/2022

DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-2922
https://github.com/dnnsoftware/dnn.pla…

[lief] LIEF vulnerable to denial of service through segmentation fault

  • Posted inMODERATE
  • Posted byGitHub
  • 10/01/202210/07/2022

A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file. A patch is available at commit number 24935f654f6df7…

Posts navigation

Previous Posts 1 … 17 18 19 20 21 … 51 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close