Show filters
753 Total Results
Displaying 51-60 of 753
Sort by:
Attacker Value
Unknown
CVE-2022-31036
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive YAML files from Argo CD's repo-server. A malicious Argo CD user with write access for a repository which is (or may be) used in a Helm-type Application may commit a symlink which points to an out-of-bounds file. If the target file is a valid YAML file, the attacker can read the contents of that file. Sensitive files which could be leaked include manifest files from other Applications' source repositories (potentially decrypted files, if you are using a decryption plugin) or any YAML-formatted secrets which have been mounted as files on the repo-server. Patches for this vulnerability has been released in the following Argo CD versions: v2.4.1, v2.3.5, v2.2.10 and v2.1.16. If you are using a version >=v2.3.0 and do not have any Helm-type Applications you ma…
0
Attacker Value
Unknown
CVE-2022-33069
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.
0
Attacker Value
Unknown
CVE-2022-33024
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
0
Attacker Value
Unknown
CVE-2022-31009
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when converting an integer value into the corresponding enum value, causing an exception instead of a fallback to a default value. This issue is fixed in [wire-ios](https://github.com/wireapp/wire-ios/commit/caa0e27dbe51f9edfda8c7a9f017d93b8cfddefb) and in Wire for iOS 3.100. There is no workaround available, but users may use other Wire clients (such as the [web app](https://app.wire.com)) to continue using Wire, or upgrade their client.
0
Attacker Value
Unknown
CVE-2021-40510
Disclosure Date: June 21, 2022 (last updated February 23, 2025)
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
0
Attacker Value
Unknown
CVE-2022-34000
Disclosure Date: June 19, 2022 (last updated February 23, 2025)
libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.
0
Attacker Value
Unknown
CVE-2021-45024
Disclosure Date: June 17, 2022 (last updated February 23, 2025)
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
0
Attacker Value
Unknown
CVE-2022-22317
Disclosure Date: June 17, 2022 (last updated February 23, 2025)
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
0
Attacker Value
Unknown
CVE-2022-22318
Disclosure Date: June 17, 2022 (last updated February 23, 2025)
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
0
Attacker Value
Unknown
CVE-2021-41411
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
0