Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
Category Archives: Advisories
CVE-2021-33420
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
davix-0.8.3-1.el7
FEDORA-EPEL-2022-2b4c6176d0
Packages in this update:
davix-0.8.3-1.el7
Update description:
Davix 0.8.3
davix-0.8.3-1.el8
FEDORA-EPEL-2022-5d08436b7d
Packages in this update:
davix-0.8.3-1.el8
Update description:
Davix 0.8.3
firefox-108.0-2.fc37
FEDORA-2022-3ae298b728
Packages in this update:
firefox-108.0-2.fc37
Update description:
New upstream release (108.0)
firefox-108.0-2.fc36
FEDORA-2022-7f424ef67a
Packages in this update:
firefox-108.0-2.fc36
Update description:
New upstream release (108.0)
golang-1.19.4-1.fc37
FEDORA-2022-3b4c68d85d
Packages in this update:
golang-1.19.4-1.fc37
Update description:
go1.19.4 (released 2022-12-06) includes security fixes to the net/http and os packages, as well as bug fixes to the compiler, the runtime, and the crypto/x509, os/exec, and sync/atomic packages. See the Go 1.19.4 milestone on the upstream issue tracker for details.
golang-1.18.9-1.fc36
FEDORA-2022-6d2b6ad1a6
Packages in this update:
golang-1.18.9-1.fc36
Update description:
go1.18.9 (released 2022-12-06) includes security fixes to the net/http and os packages, as well as bug fixes to cgo, the compiler, the runtime, and the crypto/x509 and os/exec packages. See the Go 1.18.9 milestone on the upstream issue tracker for details.
USN-5782-1: Firefox vulnerabilities
It was discovered that Firefox was using an out-of-date libusrsctp library.
An attacker could possibly use this library to perform a reentrancy issue
on Firefox. (CVE-2022-46871)
Nika Layzell discovered that Firefox was not performing a check on paste
received from cross-processes. An attacker could potentially exploit this
to obtain sensitive information. (CVE-2022-46872)
Pete Freitag discovered that Firefox did not implement the unsafe-hashes
CSP directive. An attacker who was able to inject markup into a page
otherwise protected by a Content Security Policy may have been able to
inject an executable script. (CVE-2022-46873)
Matthias Zoellner discovered that Firefox was not keeping the filename
ending intact when using the drag-and-drop event. An attacker could
possibly use this issue to add a file with a malicious extension, leading
to execute arbitrary code. (CVE-2022-46874)
Hafiizh discovered that Firefox was not handling fullscreen notifications
when the browser window goes into fullscreen mode. An attacker could
possibly use this issue to spoof the user and obtain sensitive information.
(CVE-2022-46877)
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2022-46878,
CVE-2022-46879)
ZDI-22-1666: Canon imageCLASS MF644Cdw BJNP Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw printers. Authentication is not required to exploit this vulnerability.