Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-27242

A vulnerability has been identified in OpenV2G (V0.9.4). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory corruption.

CVE
#vulnerability#js#pdf#buffer_overflow

%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 646.963 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 598.838 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 479.608 null] >> endobj 6 0 obj << /D [2 0 R /XYZ 70.866 420.525 null] >> endobj 7 0 obj << /D [8 0 R /XYZ 85.039 479.479 null] >> endobj 9 0 obj << /D [8 0 R /XYZ 70.866 195.109 null] >> endobj 10 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 11 0 R /Type /Page /Resources 12 0 R /Parent 13 0 R /Annots [14 0 R 15 0 R 16 0 R 17 0 R 18 0 R 19 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 14 0 obj << /A << /S /URI /Type /Action /URI (https://sourceforge.net/projects/openv2g/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 497.876 484.993 510.783] >> endobj 15 0 obj << /A << /S /GoTo /D (section*.2) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [386.143 437.342 524.579 448.878] >> endobj 16 0 obj << /A << /S /GoTo /D (section*.4) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [147.498 419.529 309.548 430.946] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/cert/operational-guidelines-industrial-security) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [164.798 328.453 487.754 339.989] >> endobj 18 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/industrialsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [406.699 298.684 525.406 310.102] >> endobj 12 0 obj << /ProcSet [/PDF /Text] /Font << /F51 20 0 R /F48 21 0 R >> >> endobj 11 0 obj << /Filter /FlateDecode /Length 2127 >> stream xڵYKs�6��W�TUopn��rv<�J�S��8-s�����ʿ�n�I�b8��`����|� E�*��Og?���? �$VL��@G�(�8&��`� ���,ݤ�b4fڄ�t��Gc*ì�� M�/Y��A�~��������r�(/��#�z>�}������gE} ��4Xlξ�Kx�K���~� ��D ��`v����+U]2Q=-� �i��8����4���B뺁dL�2�@��Xsō��^!*%�l�⒀�k�%��$B�(��OUD�4Mn� �����)�`��4�Kݡ��:D�f��Se)������s����ML��’��9�bP���R��Ym�?�T���4O�gk�W��ZF�)Zp�� �2btܧ ��&5=����d~+�� Ÿ��Y�6a�>����bo�H�ǜ/ ��* P�����u�Hl Z��L��p�,dc�H��E@�RC��韓�tsn�Ԕ�%}���<���#�i^��0[PC�J��=�fn� '�����’��.GZ�"����J@�Ъ��г|����ƥJ2�M����L�#����-���X�!�/���������؁O��n�/�h�{,_G���܏T���ݶL2���)q�k���#N��nl�2^FL�ȷ(���W���n�pi�����))�U��_b�����d��2Y��?�nl%HE \�S��9�>3�V)�$�q������[G��)��UX7�S�o�t�B�,�|�{���S��(��蛥��e%m���*K/�Ҥ.�]%j ��-�PTJtF�b���VCb�D�T�D�o��ǏW�ˎ��b�!+C>`�+�sF(^Q�%���035��M1�n/�/� 0��T�E� � �o�W�n�[��a{Ơ�9 8c��8��H�GaB�&�������헎��f J9�s q��F��W����� "�AE�D��d������U��6js�~ח�qưh���< k~e�Zۢ-"(��m�g ���"����6 -z����-Cd��#�b0%7��=Xl��’�G�C4-2>_fIw�,!J5 ?����B������PxJկ�".b���l�}TQ݋l��ыl|�g���N ��,n{���F��g�C ���w$V�I��*oc��ߥX�����5mU�Oe�\|8?w���V)n/�M���|�_ؗŹ-�`O����q�T���6yV(!R���

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907