Aggregator
Akira
1 year 7 months ago
cohenido
CVE-2022-23484 | Neutrinolabs xrdp up to 0.9.20 xrdp_mm_process_rail_update_window_text integer overflow (GHSA-rqfx-5fv8-q9c6 / Nessus ID 211003)
1 year 7 months ago
A vulnerability was found in Neutrinolabs xrdp up to 0.9.20. It has been classified as critical. This affects the function xrdp_mm_process_rail_update_window_text. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2022-23484. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23493 | Neutrinolabs xrdp up to 0.9.20 xrdp_mm_trans_process_drdynvc_channel_close out-of-bounds (GHSA-59wp-3wq6-jh5v / Nessus ID 211003)
1 year 7 months ago
A vulnerability was found in Neutrinolabs xrdp up to 0.9.20. It has been declared as critical. This vulnerability affects the function xrdp_mm_trans_process_drdynvc_channel_close. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2022-23493. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23480 | Neutrinolabs xrdp up to 0.9.20 devredir_proc_client_devlist_announce_req buffer overflow (GHSA-3jmx-f6hv-95wg / Nessus ID 211003)
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in Neutrinolabs xrdp up to 0.9.20. This issue affects the function devredir_proc_client_devlist_announce_req. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2022-23480. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23481 | Neutrinolabs xrdp up to 0.9.20 xrdp_caps_process_confirm_active out-of-bounds (GHSA-hm75-9jcg-p7hq / Nessus ID 211003)
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in Neutrinolabs xrdp up to 0.9.20. Affected is the function xrdp_caps_process_confirm_active. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2022-23481. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23482 | Neutrinolabs xrdp up to 0.9.20 xrdp_sec_process_mcs_data_CS_CORE out-of-bounds (GHSA-56pq-2pm9-7fhm / Nessus ID 211003)
1 year 7 months ago
A vulnerability has been found in Neutrinolabs xrdp up to 0.9.20 and classified as problematic. Affected by this vulnerability is the function xrdp_sec_process_mcs_data_CS_CORE. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2022-23482. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23483 | Neutrinolabs xrdp up to 0.9.20 libxrdp_send_to_channel out-of-bounds (GHSA-38rw-9ch2-fcxq / Nessus ID 211003)
1 year 7 months ago
A vulnerability was found in Neutrinolabs xrdp up to 0.9.20 and classified as critical. Affected by this issue is the function libxrdp_send_to_channel. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2022-23483. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23479 | Neutrinolabs xrdp up to 0.9.20 xrdp_mm_chan_data_in buffer overflow (GHSA-pgx2-3fjj-fqqh / Nessus ID 211003)
1 year 7 months ago
A vulnerability classified as critical was found in Neutrinolabs xrdp up to 0.9.20. This vulnerability affects the function xrdp_mm_chan_data_in. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2022-23479. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-2003 | Delegate up to 8.9.2 SSLway Filter sslway.c ssl_prcert subject/issuer memory corruption (EDB-24095 / XFDB-16078)
1 year 7 months ago
A vulnerability classified as critical has been found in Delegate up to 8.9.2. Affected is the function ssl_prcert of the file sslway.c of the component SSLway Filter. The manipulation of the argument subject/issuer leads to memory corruption.
This vulnerability is traded as CVE-2004-2003. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-23468 | Neutrinolabs xrdp up to 0.9.20 xrdp_login_wnd_create buffer overflow (GHSA-8c2f-mw8m-qpx6 / Nessus ID 211003)
1 year 7 months ago
A vulnerability was found in Neutrinolabs xrdp up to 0.9.20. It has been declared as critical. Affected by this vulnerability is the function xrdp_login_wnd_create. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2022-23468. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23477 | Neutrinolabs xrdp up to 0.9.20 audin_send_open buffer overflow (GHSA-hqw2-jx2c-wrr2 / Nessus ID 211003)
1 year 7 months ago
A vulnerability was found in Neutrinolabs xrdp up to 0.9.20. It has been rated as critical. Affected by this issue is the function audin_send_open. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2022-23477. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23478 | Neutrinolabs xrdp up to 0.9.20 xrdp_mm_trans_process_drdynvc_channel_open out-of-bounds write (GHSA-2f49-wwpm-78pj / Nessus ID 211003)
1 year 7 months ago
A vulnerability classified as critical has been found in Neutrinolabs xrdp up to 0.9.20. This affects the function xrdp_mm_trans_process_drdynvc_channel_open. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2022-23478. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-21797 | joblib up to 1.1.x Parallel Remote Code Execution (Issue 1128 / Nessus ID 211014)
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in joblib up to 1.1.x. This issue affects the function Parallel. The manipulation leads to Remote Code Execution.
The identification of this vulnerability is CVE-2022-21797. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-33748 | Xen Lock denial of service (FEDORA-2022-5b594b82ac / Nessus ID 211008)
1 year 7 months ago
A vulnerability classified as problematic has been found in Xen. Affected is an unknown function of the component Lock Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2022-33748. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-33747 | Xen p2m Mapping memory allocation (FEDORA-2022-5b594b82ac / Nessus ID 211008)
1 year 7 months ago
A vulnerability, which was classified as problematic, has been found in Xen. Affected by this issue is some unknown functionality of the component p2m Mapping Handler. The manipulation leads to uncontrolled memory allocation.
This vulnerability is handled as CVE-2022-33747. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-33746 | Xen p2m Mapping denial of service (FEDORA-2022-5b594b82ac / Nessus ID 211008)
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in Xen. This affects an unknown part of the component p2m Mapping Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2022-33746. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-34055 | Cyrus IMAPd up to 3.8.2 Command resource consumption (Nessus ID 211015)
1 year 7 months ago
A vulnerability was found in Cyrus IMAPd up to 3.8.2. It has been declared as problematic. This vulnerability affects unknown code of the component Command Handler. The manipulation leads to resource consumption.
This vulnerability was named CVE-2024-34055. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-21658 | Rust up to 1.58.0 std::fs::remove_dir_all toctou (GHSA-r9cc-f5pr-p3j2 / Nessus ID 211025)
1 year 7 months ago
A vulnerability classified as problematic was found in Rust up to 1.58.0. Affected by this vulnerability is the function std::fs::remove_dir_all. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2022-21658. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11306 | Altenergy Power Control Software up to 20241108 database improper authorization
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2024-11306. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
It is recommended to apply restrictive firewalling.
Other endpoints might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com