what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 126 - 150 of 281 RSS Feed

Files Date: 2022-07-01 to 2022-07-31

Apple Security Advisory 2022-07-20-2
Posted Jul 22, 2022
Authored by Apple | Site apple.com

Apple Security Advisory 2022-07-20-2 - macOS Monterey 12.5 addresses bypass, code execution, information leakage, null pointer, out of bounds read, out of bounds write, and spoofing vulnerabilities.

tags | advisory, spoof, vulnerability, code execution
systems | apple
advisories | CVE-2021-28544, CVE-2022-2294, CVE-2022-24070, CVE-2022-26981, CVE-2022-29046, CVE-2022-29048, CVE-2022-32785, CVE-2022-32786, CVE-2022-32787, CVE-2022-32789, CVE-2022-32792, CVE-2022-32793, CVE-2022-32796, CVE-2022-32797
SHA-256 | 30c718236aa0303e2a848ca5f0ff62300fca488eb543994c74cf586178d456d5
Apple Security Advisory 2022-07-20-1
Posted Jul 22, 2022
Authored by Apple | Site apple.com

Apple Security Advisory 2022-07-20-1 - iOS 15.6 and iPadOS 15.6 addresses buffer overflow, bypass, code execution, information leakage, null pointer, out of bounds read, out of bounds write, and spoofing vulnerabilities.

tags | advisory, overflow, spoof, vulnerability, code execution
systems | apple, ios
advisories | CVE-2022-2294, CVE-2022-26768, CVE-2022-26981, CVE-2022-32784, CVE-2022-32785, CVE-2022-32787, CVE-2022-32788, CVE-2022-32792, CVE-2022-32793, CVE-2022-32802, CVE-2022-32810, CVE-2022-32813, CVE-2022-32814, CVE-2022-32815
SHA-256 | e78e010a4bea2ea77407fa1f36dd85e44d56dc1216952e6d8cdb14def80805a3
Ubuntu Security Notice USN-5529-1
Posted Jul 21, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5529-1 - It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Yongkang Jia discovered that the KVM hypervisor implementation in the Linux kernel did not properly handle guest TLB mapping invalidation requests in some situations. An attacker in a guest VM could use this to cause a denial of service in the host OS.

tags | advisory, denial of service, arbitrary, kernel, local
systems | linux, ubuntu
advisories | CVE-2022-1652, CVE-2022-1679, CVE-2022-1789, CVE-2022-1852, CVE-2022-1973, CVE-2022-2078, CVE-2022-21123, CVE-2022-21125, CVE-2022-21166
SHA-256 | 900c9467490b73751623ae9022791a89235180da8de86cdb02eda9d2d8d16654
Chrome Scope Break
Posted Jul 21, 2022
Authored by Google Security Research, Mark Brand

Chrome has an issue where raw_ptr broke implicit scoped_refptr for receivers in base::Bind.

tags | exploit
advisories | CVE-2022-2156
SHA-256 | 608734695dfbbf56d37a25c6b0e92ec571e720ac20c50496dd9608c3ee36b587
Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) Remote Root
Posted Jul 21, 2022
Authored by LiquidWorm | Site zeroscience.mk

Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) versions 1.31.460 and below suffer from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user via the name GET parameter in delsnap.pl Perl/CGI script which is used for deleting snapshots taken from the webcam.

tags | exploit, arbitrary, shell, cgi, root, perl
advisories | CVE-2022-34753
SHA-256 | d419b1daf53d0f565d05d6ba8ea75d7ee176ccb9140c55fa6180d7f9532dc155
CodoForum 5.1 Remote Code Execution
Posted Jul 21, 2022
Authored by Krish Pandey

CodoForum version 5.1 suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
advisories | CVE-2022-31854
SHA-256 | 045098f70a6461ea548965fba279c18d47668837e82112dbf85f351b43ee5baf
AIEngine 2.2.0
Posted Jul 21, 2022
Authored by Luis Campo Giralte | Site bitbucket.org

AIEngine is a packet inspection engine with capabilities of learning without any human intervention. It helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.

Changes: Fixed issue with tagging flows and issue with flow identifier on the API. Now shows the current script code over the API. Added parameter class to the help URI. Added Cache-Control header on the API. Improvements on the SSLProtocol. Multiple other updates.
tags | tool
systems | unix
SHA-256 | e51bc7defd4393939e716c60405cf72a4aa1c727b6ccde44784fd235022e5017
OctoBot WebInterface 0.4.3 Remote Code Execution
Posted Jul 21, 2022
Authored by Samy Younsi, Thomas Knudsen

OctoBot WebInterface version 0.4.3 suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
advisories | CVE-2021-36711
SHA-256 | e44b74ee9184e1f4fa497f4876744c69864ed4d789de8a18313422be9a4ad1c5
Kite 1.2021.610.0 Unquoted Service Path
Posted Jul 21, 2022
Authored by Ghaleb Al-otaibi

Kite version 1.2021.610.0 suffers from an unquoted service path vulnerability.

tags | exploit
SHA-256 | f6c26ab826fa44ce94b3128d1027703b3451aafa787d124ff97ae6903c5c30b1
Red Hat Security Advisory 2022-5673-01
Posted Jul 21, 2022
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2022-5673-01 - Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. Issues addressed include a code execution vulnerability.

tags | advisory, code execution
systems | linux, redhat
advisories | CVE-2021-3634, CVE-2021-3737, CVE-2021-40528, CVE-2021-41103, CVE-2021-4189, CVE-2021-43565, CVE-2022-1271, CVE-2022-1621, CVE-2022-1629, CVE-2022-22576, CVE-2022-25313, CVE-2022-25314, CVE-2022-26945, CVE-2022-27774
SHA-256 | e6a4b0b59b2757ea6ef380429f73c2819e182dbd4e1d06bf09b8c22eac8f952b
Dr. Fone 4.0.8 Unquoted Service Path
Posted Jul 21, 2022
Authored by Esant1490

Dr. Fone version 4.0.8 suffers from an unquoted service path vulnerability.

tags | exploit
SHA-256 | a395c8c5023e9fa3ade5d03f2adda3d54bb86b40825eb131695b52008175f74a
IOTransfer 4.0 Remote Code Execution
Posted Jul 21, 2022
Authored by Tomer Peled

IOTransfer version 4.0 suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
advisories | CVE-2022-24562
SHA-256 | c710e2da6c6ed4ef7a63d1d4f9778557d2652281b2fc26cee33fa39fd5d1ca51
DASDEC Cross Site Scripting / HTML Injection
Posted Jul 21, 2022
Authored by Ken Pyle

The Monroe Electronics / Digital Alert Systems OneNet SE DASDEC Emergency Alert System Appliance suffers from cross site scripting and html injection vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 82f6d98418853066b6a98235aa9b2f3a0913d729dcbf7cc7b1e70d395b6a8bad
Ubuntu Security Notice USN-5528-1
Posted Jul 20, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5528-1 - It was discovered that FreeType did not correctly handle certain malformed font files. If a user were tricked into using a specially crafted font file, a remote attacker could cause FreeType to crash, or possibly execute arbitrary code.

tags | advisory, remote, arbitrary
systems | linux, ubuntu
advisories | CVE-2022-27404
SHA-256 | e4399fee1fafb757db2cc7084bced0d8077ec2ee656c7d3e483d74589880986a
Ubuntu Security Notice USN-5525-1
Posted Jul 20, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5525-1 - It was discovered that Apache XML Security for Java incorrectly passed a configuration property when creating specific key elements. This allows an attacker to abuse an XPath Transform to extract sensitive information.

tags | advisory, java
systems | linux, ubuntu
advisories | CVE-2021-40690
SHA-256 | 5a7567c51fc5535217fe76db85a30037524b5faac7d584fbe7e0d988cc43929b
Ubuntu Security Notice USN-5527-1
Posted Jul 20, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5527-1 - It was discovered that Checkmk incorrectly handled authentication. An attacker could possibly use this issue to cause a race condition leading to information disclosure. It was discovered that Checkmk incorrectly handled certain inputs. An attacker could use these cross-site scripting issues to inject arbitrary html or javascript code to obtain sensitive information including user information, session cookies and valid credentials.

tags | advisory, arbitrary, javascript, xss, info disclosure
systems | linux, ubuntu
advisories | CVE-2017-14955, CVE-2021-40906, CVE-2022-24565
SHA-256 | 45daf753e998edd792b4728e6f35f35c6493b1e6cc974ee1082da7f33c59b2dc
Ubuntu Security Notice USN-5526-1
Posted Jul 20, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5526-1 - Aapo Oksman discovered that PyJWT incorrectly handled signatures constructed from SSH public keys. A remote attacker could use this to forge a JWT signature.

tags | advisory, remote
systems | linux, ubuntu
advisories | CVE-2022-29217
SHA-256 | 9f4662cb5a95ee03ce93366d52dac96d27a5c0d5e8a2c08609919e3ec43b155f
Emporium eCommerce Online Shopping CMS 1.2 SQL Injection
Posted Jul 20, 2022
Authored by CraCkEr

Emporium eCommerce Online Shopping CMS version 1.2 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | fb0f85b86fd9b86364521ebf50d5426b97f071383915691f325e4d51fddad0af
GNUnet P2P Framework 0.17.2
Posted Jul 20, 2022
Authored by Christian Grothoff | Site ovmj.org

GNUnet is a peer-to-peer framework with focus on providing security. All peer-to-peer messages in the network are confidential and authenticated. The framework provides a transport abstraction layer and can currently encapsulate the network traffic in UDP (IPv4 and IPv6), TCP (IPv4 and IPv6), HTTP, or SMTP messages. GNUnet supports accounting to provide contributing nodes with better service. The primary service build on top of the framework is anonymous file sharing.

Changes: This is a bugfix release for gnunet 0.17.1.
tags | tool, web, udp, tcp, peer2peer
systems | unix
SHA-256 | 38b13b578e2490a99222757c64727deb97939fdf797107f986287c2944ee7541
Ubuntu Security Notice USN-5524-1
Posted Jul 19, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5524-1 - It was discovered that HarfBuzz incorrectly handled certain glyph sizes. A remote attacker could use this issue to cause HarfBuzz to crash, resulting in a denial of service.

tags | advisory, remote, denial of service
systems | linux, ubuntu
advisories | CVE-2022-33068
SHA-256 | 4c4fae4fa3c048260e235464283b6c18557a2219f5b8da6dbb3146bb711e7c94
Ubuntu Security Notice USN-5523-1
Posted Jul 19, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5523-1 - It was discovered that LibTIFF was not properly performing checks to guarantee that allocated memory space existed, which could lead to a NULL pointer dereference via a specially crafted file. An attacker could possibly use this issue to cause a denial of service. It was discovered that LibTIFF was not properly performing checks to avoid division calculations where the denominator value was zero, which could lead to an undefined behavior situation via a specially crafted file. An attacker could possibly use this issue to cause a denial of service.

tags | advisory, denial of service
systems | linux, ubuntu
advisories | CVE-2020-19131, CVE-2020-19144, CVE-2022-0909, CVE-2022-0924, CVE-2022-22844
SHA-256 | 5a59e47169abf47600d89ed49be7fdb00d3a42d34c3e046b30db89c940dc1bea
Ubuntu Security Notice USN-5520-2
Posted Jul 19, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5520-2 - USN-5520-1 fixed a vulnerability in HTTP-Daemon. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. It was discovered that HTTP-Daemon incorrectly handled certain crafted requests. A remote attacker could possibly use this issue to perform an HTTP Request Smuggling attack.

tags | advisory, remote, web
systems | linux, ubuntu
advisories | CVE-2022-31081
SHA-256 | 79767ea7fd118b9553d3687e6f37d54e7205b3ff5a5efb43f2c04f4d87d3a8d0
Ubuntu Security Notice USN-5522-1
Posted Jul 19, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5522-1 - Several security issues were discovered in WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.

tags | advisory, remote, web, denial of service, arbitrary, javascript, code execution, xss
systems | linux, ubuntu
advisories | CVE-2022-22677
SHA-256 | 0f0f438214ff796ec27381779ba61d110957c201c68b02d7b912474263bc9aa9
Spryker Commerce OS Remote Command Execution
Posted Jul 19, 2022
Authored by David Brown, Marcelo Reyes | Site schutzwerk.com

Spryker Commerce OS with spryker/http module versions prior to 1.7.0 suffer from a remote command execution vulnerability due to a predictable value in use.

tags | exploit, remote, web
advisories | CVE-2022-28888
SHA-256 | a6d63126b4d1bdaea5938a1d895d1687c6b584abb5b278f66f4f0e3915c97bdb
2nd International Workshop On Cyber Forensics And Threat Investigations Challenges Call For Papers
Posted Jul 19, 2022
Site easychair.org

The 2nd International Workshop on Cyber Forensics and Threat Investigations Challenges will take place October 10th through the 11th, 2022.

tags | paper, conference
SHA-256 | a7c38095ed781f48c0c6ba286dca77cedb7ed92dc2f3f33ab055eb407d1baa10
Page 6 of 12
Back45678Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close