Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2023-23473: Security Bulletin: IBM InfoSphere Information Server is vulnerable to cross-site request forgery (CVE-2023-23473)

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 245400.

CVE
#vulnerability#web#windows#linux#auth#ibm
CVE-2023-40036: GHSL-2023-112, GHSL-2023-102, GHSL-2023-103, GHSL-2023-092: Buffer Overflows in Notepad++ - CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.

CVE-2021-27932: Privilege escalation on the SSL VPN Client

Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.

Gusto Recipes Management 1.5.1 Insecure Settings

Gusto Recipes Management version 1.5.1 suffers from an ignored default credential vulnerability.

Groupoffice 3.4.21 Directory Traversal

Groupoffice version 3.4.21 suffers from a directory traversal vulnerability.

Grawlix CMS 1.1.1 Cross Site Scripting

Grawlix CMS version 1.1.1 suffers from a cross site scripting vulnerability.

Gravigra CMS 1.0 SQL Injection

Gravigra CMS version 1.0 suffers from a remote SQL injection vulnerability.

Global Domains International 2.0 HTML Injection

Global Domains International version 2.0 suffers from an html injection vulnerability.

GetSimple CMS 3.3.2 Cross Site Scripting

GetSimple CMS version 3.3.2 suffers from a cross site scripting vulnerability.

G And G Corporate CMS 1.0 SQL Injection

G and G Corporate CMS version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.