Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2020-35506: security - QEMU: ESP security fixes

A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service or potential code execution with the privileges of the QEMU process.

CVE
#vulnerability#web#mac#windows#linux#red_hat#dos#git#php#auth
CVE-2021-3527: security - CVE-2021-3527 QEMU: usb: unbounded stack allocation in usbredir

A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not bounded, a malicious guest could use this flaw to influence the array length and cause the QEMU process to perform an excessive allocation on the stack, resulting in a denial of service.

CVE-2021-33470: PHP Project, PHP Projects Ideas, PHP Latest tutorials, PHP oops Concept

COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.

CVE-2020-27815: security - CVE-2020-27815 Linux kernel: jfs: array-index-out-of-bounds in dbAdjTree

A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2020-27815: security - CVE-2020-27815 Linux kernel: jfs: array-index-out-of-bounds in dbAdjTree

A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2021-29024: Files or Directories Accessible to External Parties in InvoicePlane CRM

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

CVE-2021-29023: Weak Password Recovery Mechanism in InvoicePlane CRM

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

CVE-2021-3483: security - CVE-2021-3483: Linux kernel: a use-after-free bug in nosy driver

A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected

CVE-2021-24284

The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.

CVE-2020-23995: DOCU: Releases

An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.