| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-45807 | Cri | 0.64 | 9.8 | 0.02 | Jan 13, 2022 | jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall. | ||
| CVE-2022-23131 | Cri | 0.79 | 9.1 | 0.96 | KEV | Jan 13, 2022 | In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and… | |
| CVE-2021-30285 | Cri | 0.60 | 9.3 | 0.00 | Jan 13, 2022 | Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2022-21675 | Cri | 0.00 | 9.9 | 0.03 | Jan 12, 2022 | Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially crafted archive that holds directory… | ||
| CVE-2021-45411 | Cri | 0.64 | 9.8 | 0.04 | Jan 12, 2022 | In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution. | ||
| CVE-2022-21969 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-21907 | Cri | 0.74 | 9.8 | 0.93 | Jan 11, 2022 | HTTP Protocol Stack Remote Code Execution Vulnerability | ||
| CVE-2022-21901 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2022-21855 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-21849 | Cri | 0.64 | 9.8 | 0.06 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-21846 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-43052 | Cri | 0.61 | 9.3 | 0.01 | Jan 11, 2022 | The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default… | ||
| CVE-2020-28103 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2022 | cscms v4.1 allows for SQL injection via the "page_del" function. | ||
| CVE-2020-28102 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2022 | cscms v4.1 allows for SQL injection via the "js_del" function. | ||
| CVE-2022-21669 | Cri | 0.00 | 9.1 | 0.01 | Jan 11, 2022 | PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the server. As of time of publication, the… | ||
| CVE-2022-22115 | Cri | 0.00 | 9.0 | 0.01 | Jan 10, 2022 | In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low privileged attacker can store malicious scripts in the name of the Tag. In the… | ||
| CVE-2022-22114 | Cri | 0.00 | 9.6 | 0.01 | Jan 10, 2022 | In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary scripts. These scripts are… | ||
| CVE-2021-43297 | Cri | 0.65 | 9.8 | 0.17 | Jan 10, 2022 | A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian… | ||
| CVE-2021-25032 | Cri | 0.64 | 9.8 | 0.07 | Jan 10, 2022 | The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong… | ||
| CVE-2021-24949 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2022 | The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead to SQL injection | ||
| CVE-2022-22847 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2022 | Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in a configuration that does not require authentication). | ||
| CVE-2022-22845 | Cri | 0.00 | 9.8 | 0.04 | Jan 10, 2022 | QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations. | ||
| CVE-2022-22824 | Cri | 0.00 | 9.8 | 0.03 | Jan 10, 2022 | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | ||
| CVE-2022-22823 | Cri | 0.00 | 9.8 | 0.03 | Jan 10, 2022 | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | ||
| CVE-2022-22822 | Cri | 0.00 | 9.8 | 0.05 | Jan 10, 2022 | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | ||
| CVE-2022-22817 | Cri | 0.57 | 9.8 | 0.03 | Jan 10, 2022 | PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used. | ||
| CVE-2021-45334 | Cri | 0.64 | 9.8 | 0.03 | Jan 10, 2022 | Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection | ||
| CVE-2021-45003 | Cri | 0.64 | 9.8 | 0.03 | Jan 10, 2022 | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload. | ||
| CVE-2021-42392 | Cri | 0.70 | 9.8 | 0.83 | Jan 10, 2022 | The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited… | ||
| CVE-2021-40010 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2022 | The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution. | ||
| CVE-2021-39996 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2022 | There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow. | ||
| CVE-2021-39993 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2022 | There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2021-23594 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2022 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. | ||
| CVE-2021-23543 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2022 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. | ||
| CVE-2021-46067 | Cri | 0.64 | 9.8 | 0.05 | Jan 6, 2022 | In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover. | ||
| CVE-2021-45456 | Cri | 0.64 | 9.8 | 0.89 | Jan 6, 2022 | Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may cause an illegal… | ||
| CVE-2021-31522 | Cri | 0.64 | 9.8 | 0.03 | Jan 6, 2022 | Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions. | ||
| CVE-2022-22704 | Cri | 0.64 | 9.8 | 0.01 | Jan 6, 2022 | The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration. | ||
| CVE-2021-41842 | Cri | 0.64 | 9.8 | 0.02 | Jan 6, 2022 | An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check. | ||
| CVE-2021-43779 | Cri | 0.65 | 9.9 | 0.09 | Jan 5, 2022 | GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command… | ||
| CVE-2022-21644 | Cri | 0.00 | 9.1 | 0.01 | Jan 4, 2022 | USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site… | ||
| CVE-2022-21643 | Cri | 0.00 | 10.0 | 0.01 | Jan 4, 2022 | USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users… | ||
| CVE-2021-43832 | Cri | 0.65 | 10.0 | 0.03 | Jan 4, 2022 | Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a pipeline and execute it without authentication. If users… | ||
| CVE-2021-24042 | Cri | 0.64 | 9.8 | 0.01 | Jan 4, 2022 | The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have… | ||
| CVE-2022-0086 | Cri | 0.57 | 9.8 | 0.01 | Jan 4, 2022 | uppy is vulnerable to Server-Side Request Forgery (SSRF) | ||
| CVE-2021-45389 | Cri | 0.64 | 9.8 | 0.01 | Jan 4, 2022 | A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864. | ||
| CVE-2021-43711 | Cri | 0.67 | 9.8 | 0.38 | Jan 4, 2022 | The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution. | ||
| CVE-2021-40525 | Cri | 0.59 | 9.1 | 0.04 | Jan 4, 2022 | Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and… | ||
| CVE-2021-39990 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2022 | The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience. | ||
| CVE-2021-39982 | Cri | 0.59 | 9.1 | 0.01 | Jan 3, 2022 | Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications. |
- risk 0.64cvss 9.8epss 0.02
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
- risk 0.79cvss 9.1epss 0.96
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and…
- risk 0.60cvss 9.3epss 0.00
Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
- risk 0.00cvss 9.9epss 0.03
Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially crafted archive that holds directory…
- risk 0.64cvss 9.8epss 0.04
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.74cvss 9.8epss 0.93
HTTP Protocol Stack Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.06
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.61cvss 9.3epss 0.01
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default…
- risk 0.64cvss 9.8epss 0.01
cscms v4.1 allows for SQL injection via the "page_del" function.
- risk 0.64cvss 9.8epss 0.01
cscms v4.1 allows for SQL injection via the "js_del" function.
- risk 0.00cvss 9.1epss 0.01
PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the server. As of time of publication, the…
- risk 0.00cvss 9.0epss 0.01
In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low privileged attacker can store malicious scripts in the name of the Tag. In the…
- risk 0.00cvss 9.6epss 0.01
In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary scripts. These scripts are…
- risk 0.65cvss 9.8epss 0.17
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian…
- risk 0.64cvss 9.8epss 0.07
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong…
- risk 0.64cvss 9.8epss 0.02
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead to SQL injection
- risk 0.64cvss 9.8epss 0.01
Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in a configuration that does not require authentication).
- risk 0.00cvss 9.8epss 0.04
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.
- risk 0.00cvss 9.8epss 0.03
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- risk 0.00cvss 9.8epss 0.03
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- risk 0.00cvss 9.8epss 0.05
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- risk 0.57cvss 9.8epss 0.03
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
- risk 0.64cvss 9.8epss 0.03
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection
- risk 0.64cvss 9.8epss 0.03
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.
- risk 0.70cvss 9.8epss 0.83
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited…
- risk 0.64cvss 9.8epss 0.01
The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution.
- risk 0.64cvss 9.8epss 0.01
There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.
- risk 0.64cvss 9.8epss 0.01
There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.64cvss 9.8epss 0.02
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
- risk 0.64cvss 9.8epss 0.02
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
- risk 0.64cvss 9.8epss 0.05
In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
- risk 0.64cvss 9.8epss 0.89
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may cause an illegal…
- risk 0.64cvss 9.8epss 0.03
Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
- risk 0.64cvss 9.8epss 0.01
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check.
- risk 0.65cvss 9.9epss 0.09
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command…
- risk 0.00cvss 9.1epss 0.01
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site…
- risk 0.00cvss 10.0epss 0.01
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users…
- risk 0.65cvss 10.0epss 0.03
Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a pipeline and execute it without authentication. If users…
- risk 0.64cvss 9.8epss 0.01
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have…
- risk 0.57cvss 9.8epss 0.01
uppy is vulnerable to Server-Side Request Forgery (SSRF)
- risk 0.64cvss 9.8epss 0.01
A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.
- risk 0.67cvss 9.8epss 0.38
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
- risk 0.59cvss 9.1epss 0.04
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and…
- risk 0.64cvss 9.8epss 0.01
The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.
- risk 0.59cvss 9.1epss 0.01
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.