2b45 / vuln-list

0 stars 0 forks source link

【2022-01-06 17:32:50.833801】抓取 1 天内的NVD数据 #11

Open gmctl opened 2 years ago

gmctl commented 2 years ago
CVE 描述 更新时间
[CVE-2021-46144](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-46144
) Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences. 2022-01-06 05:15:09+00:00
[CVE-2022-0122](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-0122
) forge is vulnerable to URL Redirection to Untrusted Site 2022-01-06 05:15:09+00:00
[CVE-2022-22704](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-22704
) The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration. 2022-01-06 05:15:09+00:00
[CVE-2021-46143](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-46143
) In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. 2022-01-06 04:15:07+00:00
[CVE-2021-46141](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-46141
) An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. 2022-01-06 04:15:06+00:00
[CVE-2021-46142](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-46142
) An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. 2022-01-06 04:15:06+00:00
[CVE-2022-0121](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-0121
) hoppscotch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor 2022-01-06 03:15:06+00:00
[CVE-2021-43947](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-43947
) Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3. 2022-01-06 01:15:07+00:00
[CVE-2020-23986](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-23986
) Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError. 2022-01-06 00:15:07+00:00
[CVE-2020-27428](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-27428
) A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted sb3 file. 2022-01-06 00:15:07+00:00
[CVE-2021-41842](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-41842
) An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check. 2022-01-06 00:15:07+00:00
[CVE-2021-45971](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45971
) An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (CommBufferData). 2022-01-06 00:15:07+00:00
[CVE-2021-45969](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45969
) An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the CommBuffer+8 location). 2022-01-05 23:15:08+00:00
[CVE-2021-45970](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45970
) An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the status code saved at the CommBuffer+4 location). 2022-01-05 23:15:08+00:00
[CVE-2021-46038](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-46038
) A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, which causes a Denial of Service (context-dependent). 2022-01-05 23:15:08+00:00
[CVE-2020-5956](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-5956
) An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer. 2022-01-05 23:15:07+00:00
[CVE-2021-45832](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45832
) A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (context-dependent). 2022-01-05 21:15:07+00:00
[CVE-2021-45833](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45833
) A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent). 2022-01-05 21:15:07+00:00
[CVE-2022-21653](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21653
) Jawn is an open source JSON parser. Extenders of the org.typelevel.jawn.SimpleFacade and org.typelevel.jawn.MutableFacade who don't override objectContext() are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. jawn-parser-1.3.1 fixes this issue and users are advised to upgrade. For users unable to upgrade override objectContext() to use a collision-safe collection. 2022-01-05 21:15:07+00:00
[CVE-2022-21651](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21651
) Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There is no workaround and users are advised to upgrade as soon as possible. 2022-01-05 20:15:08+00:00
[CVE-2022-21652](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21652
) Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue. 2022-01-05 20:15:08+00:00
[CVE-2021-45830](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45830
) A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service. 2022-01-05 20:15:07+00:00
[CVE-2021-45831](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45831
) A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Service. 2022-01-05 20:15:07+00:00
[CVE-2022-21642](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21642
) Discourse is an open source platform for community discussion. In affected versions when composing a message from topic the composer user suggestions reveals whisper participants. The issue has been patched in stable version 2.7.13 and beta version 2.8.0.beta11. There is no workaround for this issue and users are advised to upgrade. 2022-01-05 19:15:09+00:00
[CVE-2021-43779](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-43779
) GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin. 2022-01-05 19:15:08+00:00
[CVE-2021-43816](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-43816
) containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either /etc/hosts, /etc/hostname, or /etc/resolv.conf. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible. 2022-01-05 19:15:08+00:00