A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.
Category Archives: Advisories
firefox-106.0-1.fc35
FEDORA-2022-6df8e191d3
Packages in this update:
firefox-106.0-1.fc35
Update description:
Updated to 106.0
firefox-106.0-1.fc36
FEDORA-2022-e83147158d
Packages in this update:
firefox-106.0-1.fc36
Update description:
Updated to 106.0
firefox-106.0-1.fc37
FEDORA-2022-149b2eb8e9
Packages in this update:
firefox-106.0-1.fc37
Update description:
Updated to 106.0
kdiskmark-3.1.2-1.el8
FEDORA-EPEL-2022-e6eed63b43
Packages in this update:
kdiskmark-3.1.2-1.el8
Update description:
Update to latest version
ZDI-22-1444: Oracle VirtualBox VRDP Double Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle VirtualBox. Authentication is not required to exploit this vulnerability.
ZDI-22-1443: Oracle Access Management CustomReadServlet Directory Traversal Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Oracle Access Management. Authentication is not required to exploit this vulnerability.
ZDI-22-1442: Oracle VirtualBox COM RPC Interface Improper Access Control Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability.
ZDI-22-1441: Siemens Solid Edge Viewer DWG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
ZDI-22-1462: (Pwn2Own) Linux Kernel io_uring Improper Update of Reference Count Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.