CVE-2023-24840
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inje ...
Continue Reading
March 27, 2023
CVE-2023-24841
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulner ...
Continue Reading
March 27, 2023
CVE-2023-24837
HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject and execu ...
Continue Reading
March 27, 2023
Tenable Sensor Proxy < 1.0.7 Multiple Vulnerabilities (TNS-2023-15)
According to its self-reported version, the Tenable Sensor Proxy application running on the remote host is version 1.0.6. It is, therefore, affected by multiple vulnerabilities in OpenSSL prior to ver ...
Continue Reading
March 24, 2023
AlmaLinux 8 : openssl (ALSA-2023:1405)
The remote AlmaLinux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ALSA-2023:1405 advisory.
- A timing based side channel exists in the OpenSSL RSA ...
Continue Reading
March 24, 2023
Amazon Linux 2023 : tomcat9, tomcat9-admin-webapps, tomcat9-el-3.0-api (ALAS2023-2023-140)
It is, therefore, affected by a vulnerability as referenced in the ALAS2023-2023-140 advisory.
- If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was ...
Continue Reading
March 24, 2023
Amazon Linux 2023 : php8.1, php8.1-bcmath, php8.1-cli (ALAS2023-2023-139)
It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2023-139 advisory.
- In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() fu ...
Continue Reading
March 24, 2023
CVE-2023-26360
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the con ...
Continue Reading
March 23, 2023