Posts of last 24 hours
A vulnerability classified as critical was found in PJSIP up to 2.12.1. This affects an unknown part of the component Parser. The manipulation results in buffer overflow.
This vulnerability was named CVE-2022-39244. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/210169
A vulnerability described as problematic has been identified in Git. This issue affects some unknown processing of the component Local Clone Handler. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2022-39253. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/211777
A vulnerability classified as critical has been found in Enalean Tuleap. Impacted is an unknown function of the component Branch Prefix Update Handler. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2022-39233. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/211778
A vulnerability classified as critical has been found in Discourse. Impacted is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2022-39241. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/212856
CVE-2022-39234 | GLPI up to 10.0.3 Cookie session expiration (GHSA-pgcx-mc58-3gmg / EUVD-2022-41759)
A vulnerability was found in GLPI up to 10.0.3. It has been rated as problematic. Impacted is an unknown function of the component Cookie Handler. Performing a manipulation results in session expiration.
This vulnerability is reported as CVE-2022-39234. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
https://vuldb.com/vuln/212878
A vulnerability categorized as problematic has been discovered in cmark-gfm up to 0.29.0.gfm.5. This vulnerability affects unknown code of the component Autolink Extension. Such manipulation leads to resource consumption.
This vulnerability is documented as CVE-2022-39209. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/208707
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
Если данные подтвердятся, все модели расширения пространства придётся строить заново.
https://www.securitylab.ru/news/574215.php
A vulnerability categorized as critical has been discovered in Linux Kernel up to 7.0.12. This affects the function sctp_association_free of the component sctp. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is registered as CVE-2026-52917. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/373151
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.0.10. This issue affects the function batadv_tp_sender_shutdown of the component batman-adv. The manipulation of the argument negative leads to use after free.
This vulnerability is uniquely identified as CVE-2026-52919. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/373158