Skip to content

TechMedia

Header Image
Category

CRITICAL

104 Posts

Featured

Posted byWpmaster
[vm2] vm2 vulnerable to sandbox escape
Posted byWpmaster
[go.etcd.io/etcd/v3] Etcd-io Improper Authentication vulnerability
Posted byWpmaster
[github.com/sjqzhang/go-fastdfs] sjqzhang go-fastdfs vulnerable to path traversal
Posted byWpmaster
[knplabs/knp-snappy] PHAR deserialization allowing remote code execution

[curl] curl FTP path confusion leads to NIL byte out of bounds write

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/14/202203/02/2023

curl can be coerced into writing a zero byte out of bounds.
This bug can trigger when curl is told to work on an FTP URL, with the setting to only issue a single CWD command (–ftp-method singlecwd or the libcurl alternative CURLOPT_FTP_FILEMETHOD).
cu…

[smalruby] smalruby and smalruby-editor vulnerable to OS Command Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/13/202201/27/2023

smalruby-editor prior to 0.4.1 and smalruby prior to 0.1.11 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-2096
http://jvn.jp/en/jp/JVN50197114/index.html
http://s…

[fluentd] Fluentd Escape Sequence Injection Vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/13/202201/25/2023

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
References

https://nvd.nist.gov/vuln/detail/CVE-20…

[org.jgroups:jgroups] Improper Input Validation in JGroups

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/13/202212/14/2022

JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vec…

[pdfkit] PDFKit Improper Input Validation vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 05/05/202201/27/2023

Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability
References

https://nvd.nist.gov/vuln/detail/CVE-2013-1607
https://exchange.xforce.ibmcloud.com/vulnerabilities/82563
https://web.archive.org/web/20200229104225/https://www.securityfocus…

[Simple-Wayland-HotKey-Daemon] Insecure temporary file usage in SWHKD

  • Posted inCRITICAL
  • Posted byWpmaster
  • 04/08/202201/29/2023

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-27818
https://github.com/waycrate/swhkd/commit/f70b99dd575fab79d8a942111a6980431f006818…

[org.springframework:spring-webflux] Remote Code Execution in Spring Framework

  • Posted inCRITICAL
  • Posted byWpmaster
  • 04/01/202212/16/2022

Spring Framework prior to versions 5.2.20 and 5.3.18 contains a remote code execution vulnerability known as Spring4Shell.
Impact
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data bi…

[flumedb] Use of Uninitialized Resource in flumedb.

  • Posted inCRITICAL
  • Posted byWpmaster
  • 01/07/202201/11/2023

An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-45684
https://raw.githubusercontent.com/rustsec/advisory-db/main/cr…

[csv-sniffer] Use of Uninitialized Resource in csv-sniffer.

  • Posted inCRITICAL
  • Posted byWpmaster
  • 01/07/202201/11/2023

An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. preamble_skipcount may read from uninitialized memory locations.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-45686
https://raw.githubusercontent.com/rustsec/advisor…

[cgi] Buffer overrun in CGI.escape_html

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/15/202101/13/2023

A buffer overrun vulnerability was discovered in CGI.escape_html. This can lead to a buffer overflow when a user passes a very large string (> 700 MB) to CGI.escape_html on a platform where long type takes 4 bytes, typically, Windows.
References

ht…

Posts navigation

Previous Posts 1 … 8 9 10 11 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close