There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
Category Archives: Advisories
CVE-2020-8586
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2021-36829
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
CVE-2021-39324
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2021-39326
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution.
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.
Adobe Commerce is an offering that provides companies with a flexible and scalable end-to-end plate form to manage commerce experiences of their customers.
Adobe Acrobat and Reader are used to view, create, print, and mange PDF files.
Illustrator is a vector graphics editor and design program.
Framemaker is a document processor designed for writing and editing large or complex documents.
Premiere Elements is a video editing software similar to Premiere Pro.
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
pspp-1.6.2-4.fc37
FEDORA-2022-629b1e8b81
Packages in this update:
pspp-1.6.2-4.fc37
Update description:
Fix for CVE-2022-39831, CVE-2022-39831
pspp-1.6.2-4.fc36
FEDORA-2022-ad61bb0c42
Packages in this update:
pspp-1.6.2-4.fc36
Update description:
Fix for CVE-2022-39831, CVE-2022-39831
qt5-qtwebengine-5.15.10-1.fc35
FEDORA-2022-ae75c0ca4f
Packages in this update:
qt5-qtwebengine-5.15.10-1.fc35
Update description:
Update to latest LTS release
123ADV-001: Stack Buffer Overflow in Lotus 1-2-3 R3 for UNIX/Linux
Posted by Tavis Ormandy on Sep 05
# About
The 123 command is a spreadsheet application for UNIX-based systems that
can be used in interactive mode to create and modify financial and
scientific models.
For more information, see https://123r3.net
# Advisory
A stack buffer overflow was reported in the cell format processing
routines. If a victim opens an untrusted malicious worksheet, code
execution could occur.
There have been no reports of this vulnerability being exploited…