Skip to content

TechMedia

Header Image
Category

CRITICAL

104 Posts

Featured

Posted byWpmaster
[vm2] vm2 vulnerable to sandbox escape
Posted byWpmaster
[go.etcd.io/etcd/v3] Etcd-io Improper Authentication vulnerability
Posted byWpmaster
[github.com/sjqzhang/go-fastdfs] sjqzhang go-fastdfs vulnerable to path traversal
Posted byWpmaster
[knplabs/knp-snappy] PHAR deserialization allowing remote code execution

[replicator] replicator vulnerable to Deserialization of Untrusted Data

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/16/202212/21/2022

A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-33420
https://github.com/…

[typo3/cms] TYPO3 vulnerable to Insufficient Session Expiration

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/15/202212/20/2022

An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed.
Refe…

[io.scif:scifio] SCIFIO vulnerable to Path Traversal

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/14/202212/17/2022

A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUnpackResource of the file src/test/java/io/scif/util/DefaultSampleFilesService.java of the component ZIP File Handler. The manipulati…

[rdiffweb] Improper Privilege Management in rdiffweb

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/13/202212/16/2022

Unauthorized access to settings update, logs , history, delete etc in GitHub repository ikus060/rdiffweb prior to 2.5.2.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4314
https://github.com/ikus060/rdiffweb/commit/b2df3679564d0daa2856213bb307d…

[PaddlePaddle] PaddlePaddle vulnerable to Code Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/07/202212/10/2022

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. A patch is available on the develop branch of the repository and anticipated to be part of a 2.4 release.
References

https://nvd.nist.gov/v…

[paddlepaddle] PaddlePaddle Out-of-bounds Read vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/07/202212/10/2022

Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. A patch is available in the release/2.4 branch.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-46741
https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2022-00…

[py7zr] py7zr directory traversal vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/07/202212/10/2022

A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
References

https://nvd.nist.gov/vuln/detail/CVE-2…

[nodebb] NodeBB vulnerable to account takeover via prototype vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/06/202212/06/2022

Impact
Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts.
Patches
Patched in 2.6.1
Workarounds
Site maintainers can cherry-pick https…

[nadesiko3] nadesiko3 vulnerable to OS Command Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/05/202212/07/2022

OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.
References

https://nvd.nist.go…

[nadesiko3] Nadesiko3 OS Command Injection vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/05/202212/07/2022

OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.68 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.
Release notes for versions 3.3.62 and 3.3.69 both…

Posts navigation

Previous Posts 1 … 4 5 6 7 8 … 11 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close