Faculty of Engineering, Ferdowsi University of Mashhad, Mashhad, Khorasan Razavi, Iran

0

سبد خرید

high level and critical vulnerability (part 2) (16-19 December )

high level and critical vulnerability (part 2) (16-19 December )

CVE-2022-32749

Description

Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.

Base Score: 7.5 HIGH

https://lists.apache.org/thread/mrj2lg4s0hf027rk7gz8t7hbn9xpfg02

________________________

CVE-2022-38659

Description

In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.

Base Score: 7.8 HIGH

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102049

__________________________________

CVE-2022-4606

Description

PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.

Base Score: 9.8 CRITICAL

https://huntr.dev/bounties/3dab0466-c35d-4163-b3c7-a8666e2f7d95

_____________________________

CVE-2022-47521

Description

An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames.

Base Score: 7.8 HIGH

https://lore.kernel.org/r/[email protected]

____________________________________

CVE-2022-47520

Description

An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink packet.

Base Score: 7.1 HIGH

https://lore.kernel.org/r/[email protected]

______________________________

CVE-2022-47519

Description

An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from Wi-Fi management frames.

Base Score: 7.8 HIGH

https://lore.kernel.org/r/[email protected]

_______________________________________-

CVE-2022-47518

Description

An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames.

Base Score: 7.8 HIGH

https://lore.kernel.org/r/[email protected]

_______________________________

CVE-2022-31707

Description

vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.

Base Score: 7.2 HIGH

https://www.vmware.com/security/advisories/VMSA-2022-0034.html

__________________________________________

sourse:

https://nvd.nist.gov/vuln/detail/CVE-2021-3466

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3466

 

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles

© All rights reserved to APA Specialized Center of Ferdowsi University of Mashhad