An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.Read More ...
Continue ReadingJuly 01, 2022
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery v ...
Continue ReadingJuly 01, 2022
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.Read More ...
Continue ReadingJuly 01, 2022
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.Read More ...
Continue ReadingJuly 01, 2022
The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due ...
Continue ReadingJuly 01, 2022
All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.Read More ...
Continue ReadingJuly 01, 2022
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.Read More ...
Continue ReadingJuly 01, 2022
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.Read More ...
Continue ReadingJuly 01, 2022
Back to Main