Critical · CVSS 10
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings that usually require particular attention in term of security. Although p2 has built-in strategies to ensure artifacts are signed and then to help establish trust, there is no such strategy for the metadata part that does configure such touchpoints. As a result, it's possible to install a unit that will run malicious code during installation without user receiving any warning about this installation step being risky when coming from untrusted source.
Published Jul 8, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.
Published Jul 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
Published Jul 26, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.
Published Jul 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
Published Jul 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality.
Published Jul 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity.
Published Jul 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
Published Jul 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a buffer overflow vulnerability in eSE620X vESS V100R001C10SPC200 and V100R001C20SPC200. An attacker can exploit this vulnerability by sending a specific message to the target device due to insufficient validation of packets. Successful exploit could cause a denial of service condition.
Published Jul 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
Published Jul 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
Published Jul 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
Published Jul 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
Published Jul 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
Published Jul 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
Published Jul 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.
Published Jul 28, 2021 · Updated Aug 4, 2024
High · CVSS 7.5
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.
Published Jul 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g., tar and nc).
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocations. A remote attacker can send a malicious serialized object to the above RMI entries. The objects get deserialized without any check on the incoming data. In the worst case, it may let the attacker run arbitrary code remotely. For both jUDDI web service applications and jUDDI clients, the usage of RMI is disabled by default. Since this is an optional feature and an extension to the UDDI protocol, the likelihood of impact is low. Starting with 3.3.10, all RMI related code was removed.
Published Jul 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions by measuring timing differences.
Published Jul 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_SIZE File Contents Request PDU.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Telegram Web K Alpha 0.6.1 allows XSS via a document name.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.
Published Jul 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.
Published Jul 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
Published Jul 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
Published Jul 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.
Published Jul 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
Published Jul 25, 2021 · Updated Aug 4, 2024