| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34470 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. | ||
| CVE-2022-31748 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could… | ||
| CVE-2022-31747 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have… | ||
| CVE-2022-31737 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. | ||
| CVE-2022-31736 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. | ||
| CVE-2022-29917 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… | ||
| CVE-2022-26486 | Cri | 0.75 | 9.6 | 0.02 | KEV | Dec 22, 2022 | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0,… | |
| CVE-2022-26384 | Cri | 0.62 | 9.6 | 0.01 | Dec 22, 2022 | If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects… | ||
| CVE-2022-22759 | Cri | 0.62 | 9.6 | 0.01 | Dec 22, 2022 | If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox… | ||
| CVE-2022-1887 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101. | ||
| CVE-2021-4140 | Cri | 0.65 | 10.0 | 0.01 | Dec 22, 2022 | It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | ||
| CVE-2021-4129 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough… | ||
| CVE-2021-4127 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9. | ||
| CVE-2022-47926 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php | ||
| CVE-2022-46102 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php | ||
| CVE-2022-45966 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. | ||
| CVE-2022-45347 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has… | ||
| CVE-2022-3184 | Cri | 0.65 | 9.8 | 0.12 | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory. | ||
| CVE-2022-3183 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. | ||
| CVE-2022-40145 | Cri | 0.57 | 9.8 | 0.03 | Dec 21, 2022 | This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName)… | ||
| CVE-2022-47635 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2022 | Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient.php. | ||
| CVE-2022-25893 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2022 | The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise. | ||
| CVE-2022-47629 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2022 | Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. | ||
| CVE-2022-46327 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions. | ||
| CVE-2022-46326 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46325 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46324 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46323 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46320 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2022 | The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting. | ||
| CVE-2022-46319 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2022 | Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write. | ||
| CVE-2022-46316 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2022 | A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | ||
| CVE-2022-46020 | Cri | 0.67 | 9.8 | 0.39 | Dec 20, 2022 | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | ||
| CVE-2022-46538 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2022 | Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac. | ||
| CVE-2022-40624 | Cri | 0.65 | 9.8 | 0.17 | Dec 20, 2022 | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814. | ||
| CVE-2022-46421 | Cri | 0.57 | 9.8 | 0.03 | Dec 20, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0. | ||
| CVE-2022-44109 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int). | ||
| CVE-2022-44108 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc. | ||
| CVE-2022-44940 | Cri | 0.52 | 9.1 | 0.01 | Dec 19, 2022 | Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc. | ||
| CVE-2022-40434 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. | ||
| CVE-2022-28173 | Cri | 0.59 | 9.1 | 0.01 | Dec 19, 2022 | The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices. | ||
| CVE-2022-4063 | Cri | 0.64 | 9.8 | 0.10 | Dec 19, 2022 | The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers. | ||
| CVE-2022-4050 | Cri | 0.64 | 9.8 | 0.05 | Dec 19, 2022 | The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users | ||
| CVE-2022-44755 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44754 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44753 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44752 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44751 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44750 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44456 | Cri | 0.69 | 9.8 | 0.70 | Dec 19, 2022 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. | ||
| CVE-2022-4606 | Cri | 0.03 | 9.8 | 0.35 | Dec 18, 2022 | PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. |
- risk 0.64cvss 9.8epss 0.01
Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
- risk 0.64cvss 9.8epss 0.01
Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
- risk 0.64cvss 9.8epss 0.01
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have…
- risk 0.64cvss 9.8epss 0.01
A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
- risk 0.64cvss 9.8epss 0.01
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
- risk 0.64cvss 9.8epss 0.01
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
- risk 0.75cvss 9.6epss 0.02
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0,…
- risk 0.62cvss 9.6epss 0.01
If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects…
- risk 0.62cvss 9.6epss 0.01
If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox…
- risk 0.64cvss 9.8epss 0.01
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
- risk 0.65cvss 10.0epss 0.01
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- risk 0.64cvss 9.8epss 0.01
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough…
- risk 0.64cvss 9.8epss 0.01
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
- risk 0.64cvss 9.8epss 0.01
AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
- risk 0.64cvss 9.8epss 0.01
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
- risk 0.64cvss 9.8epss 0.01
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
- risk 0.64cvss 9.8epss 0.01
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has…
- risk 0.65cvss 9.8epss 0.12
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.
- risk 0.64cvss 9.8epss 0.02
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.
- risk 0.57cvss 9.8epss 0.03
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName)…
- risk 0.64cvss 9.8epss 0.01
Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient.php.
- risk 0.64cvss 9.8epss 0.01
The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.
- risk 0.64cvss 9.8epss 0.02
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
- risk 0.64cvss 9.8epss 0.01
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.01
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.01
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.01
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.01
The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
- risk 0.64cvss 9.8epss 0.01
Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
- risk 0.64cvss 9.8epss 0.01
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- risk 0.67cvss 9.8epss 0.39
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
- risk 0.64cvss 9.8epss 0.02
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.
- risk 0.65cvss 9.8epss 0.17
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
- risk 0.57cvss 9.8epss 0.03
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
- risk 0.64cvss 9.8epss 0.01
pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int).
- risk 0.64cvss 9.8epss 0.01
pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc.
- risk 0.52cvss 9.1epss 0.01
Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc.
- risk 0.64cvss 9.8epss 0.01
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
- risk 0.59cvss 9.1epss 0.01
The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
- risk 0.64cvss 9.8epss 0.10
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
- risk 0.64cvss 9.8epss 0.05
The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.69cvss 9.8epss 0.70
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.
- risk 0.03cvss 9.8epss 0.35
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.