Skip to content

Underground News

Header Image
Archive

Month: May 2022

646 Posts

Featured

Posted byUDiscoverMusic.
デフ・レパード、新作発売に合わせて新たなマッチ3パズルゲーム「Let’s Rock It」を発表
Posted byUDiscoverMusic.
【発売15周年】リアーナ『Good Girl Gone Bad』解説:大胆な変身を見せ、時代を象徴する存在となった第一歩
Posted byマイナビニュース
デル、14型の小型でNVIDIA T550搭載のモバイルワークステーション「Precision 3470」
Posted byマイナビニュース
FRONTIER、第11世代Intel Core搭載の15.6型ノートPC「NLTシリーズ」

[org.drools:drools-core] Improper Input Validation in Drools and jBPM

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/07/2022

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-8125
https…

[org.apache.solr:solr-core] Improper Limitation of a Pathname to a Restricted Directory in Apache Solr

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/08/2022

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to…

Step into the Meroë pyramids with Google

  • Posted inArts & CultureGoogle AR & VRGoogle in the Middle EastMaps
  • Posted byMariam Khaled Dabboussi
  • 05/17/2022

When you think of pyramids does your mind wander to the Pyramids of Giza in Egypt or the Mayan Temples of Guatemala? Great civilizations built each of these pyramids and inscribed their stories onto the walls of them, offering glimpses into their daily…

[org.owasp.esapi:esapi] Missing Cryptographic Step in OWASP Enterprise Security API for Java

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/08/2022

The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attac…

[requests] Exposure of Sensitive Information to an Unauthorized Actor in Requests

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/08/2022

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-1829
https://github.com/kennethreitz/request…

[org.apache.activemq:activemq-client] Improper Authentication in Apache ActiveMQ

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/09/2022

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
References

https://nvd.nist.gov/vuln/detail/CVE-2013-3060
ht…

[org.directwebremoting:dwr] Exposure of Sensitive Information to an Unauthorized Actor in Direct Web Remoting

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/07/2022

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entit…

[org.springframework:spring] Improper Control of Generation of Code (‘Code Injection’) in Spring Framework

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202206/18/2022

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar …

[notebook] Improper Input Validation in Jupyter Notebook

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/07/2022

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
References

https://nvd.nis…

[org.apache.poi:poi] Loop with Unreachable Exit Condition in Apache POI

  • Posted inUncategorized
  • Posted byGitHub
  • 05/17/202207/07/2022

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
References

https://nvd.nist.gov/vuln/detail/CVE-2014-9527
https://access.redhat.com/errata/RHSA-2016:1135…

Posts navigation

Previous Posts 1 … 38 39 40 41 42 … 65 Next Posts
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close