Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2022-28378: cms/CHANGELOG.md at develop · craftcms/cms

Craft CMS before 3.7.29 allows XSS.

CVE
#sql#xss#csrf#vulnerability#web#ios#android#mac#windows#google#amazon#redis#js#git#java
CVE-2021-26623: KISA 인터넷 보호나라&KrCERT

A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.

CVE-2022-27050: Vuln/BitComet-Unquoted-Service-Path at main · ycdxsb/Vuln

BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level.

CVE-2022-27049: Vuln/Raidrive Setup Arbitrary File Move.md at main · ycdxsb/Vuln

Raidrive before v2021.12.35 allows attackers to arbitrarily move log files by pre-creating a mountpoint and log files before Raidrive is installed.

CVE-2021-46439: EGSoftWeb.in

The WinSEGAV AutoConfig service in EG Free Antivirus v2020 suffers from a local privilege escalation vulnerability, due to unquoted paths in the service's executable path.

CVE-2021-43484: Offensive Security’s Exploit Database Archive

A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.

CVE-2021-43505

Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

CVE-2022-1176: Loose comparison causes IDOR on multiple endpoints in livehelperchat

Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

CVE-2022-28128: File encryption software for both Windows and macOS

Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

Randomizing the KUSER_SHARED_DATA Structure on Windows

Opps, this post exists, but was actually published 4/5/2022. We’re navigating you to the correct page now. If that doesn’t work click the link below: Randomizing the KUSER_SHARED_DATA Structure on Windows – Microsoft Security Response Center