Microsoft has reminded customers that Office 2016 and Office 2019 will reach the end of extended support six months from now, on October 14, 2025. [...]
A vulnerability classified as critical was found in cURL up to 7.61.1. This vulnerability affects the function Curl_close of the component Easy Handler. The manipulation leads to use after free.
This vulnerability was named CVE-2018-16840. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Netgear WNR854T 1.5.2 and classified as critical. This issue affects the function addmap_exec of the component UPNP Service. The manipulation of the argument NewInternalClient leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-54807. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability was found in Netgear WNR854T 1.5.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file post.cgi of the component Request Handler. The manipulation of the argument wan_hostname leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2024-54804. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Netgear WNR854T 1.5.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file post.cgi of the component Request Handler. The manipulation of the argument get_email leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2024-54805. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Netgear WNR854T 1.5.2. It has been classified as critical. Affected is an unknown function of the file cmd.cgi of the component Web Interface. The manipulation leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2024-54806. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Linux Kernel up to 5.18.3. It has been classified as problematic. Affected is the function kobject_init_and_add. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2022-49370. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 5.18.3. Affected is the function ubi_create_volume. The manipulation of the argument eba_tbl leads to use after free.
This vulnerability is traded as CVE-2022-49388. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 5.18.3 and classified as critical. Affected by this vulnerability is the function devm_kfree of the component st21nfca. The manipulation leads to memory leak.
This vulnerability is known as CVE-2022-49331. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Linux Kernel up to 5.18.3. Affected is the function unix_dgram_peer_wake_me of the component af_unix. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2022-49344. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.18.3. It has been classified as problematic. This affects the function of_get_child_by_name of the component mv88e6xxx_mdios_register. The manipulation leads to improper update of reference count.
This vulnerability is uniquely identified as CVE-2022-49367. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.10.110/5.15.33/5.16.19/5.17.2 and classified as problematic. Affected by this issue is the function pm8001_send_abort_all. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2022-49120. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.4.188/5.10.109/5.15.32/5.16.18/5.17.1. It has been classified as critical. This affects the function tcp_bpf_sendmsg of the file net/core/stream.c. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2022-49209. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
Microsoft warns of a malvertising campaign using Node.js to deliver info-stealing malware via fake crypto trading sites like Binance and TradingView. Microsoft has observed Node.js increasingly used in malware campaigns since October 2024, including an ongoing crypto-themed malvertising attack as of April 2025. Threat actors are increasingly using Node.js to deploy malware, shifting from traditional […]
A vulnerability classified as critical has been found in Netgear WNR854T 1.5.2. This affects the function SetDefaultConnectionService. The manipulation leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2024-54808. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in Netgear WNR854T 1.5.2 and classified as critical. This vulnerability affects the function parse_st_header of the component Header Parameter Handler. The manipulation leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2024-54809. The attack can be initiated remotely. There is no exploit available.