Show filters
753 Total Results
Displaying 51-60 of 753
Sort by:
Attacker Value
Unknown

CVE-2022-31036

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive YAML files from Argo CD's repo-server. A malicious Argo CD user with write access for a repository which is (or may be) used in a Helm-type Application may commit a symlink which points to an out-of-bounds file. If the target file is a valid YAML file, the attacker can read the contents of that file. Sensitive files which could be leaked include manifest files from other Applications' source repositories (potentially decrypted files, if you are using a decryption plugin) or any YAML-formatted secrets which have been mounted as files on the repo-server. Patches for this vulnerability has been released in the following Argo CD versions: v2.4.1, v2.3.5, v2.2.10 and v2.1.16. If you are using a version >=v2.3.0 and do not have any Helm-type Applications you ma…
Attacker Value
Unknown

CVE-2022-33069

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.
Attacker Value
Unknown

CVE-2022-33024

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
Attacker Value
Unknown

CVE-2022-31009

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when converting an integer value into the corresponding enum value, causing an exception instead of a fallback to a default value. This issue is fixed in [wire-ios](https://github.com/wireapp/wire-ios/commit/caa0e27dbe51f9edfda8c7a9f017d93b8cfddefb) and in Wire for iOS 3.100. There is no workaround available, but users may use other Wire clients (such as the [web app](https://app.wire.com)) to continue using Wire, or upgrade their client.
Attacker Value
Unknown

CVE-2021-40510

Disclosure Date: June 21, 2022 (last updated February 23, 2025)
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
Attacker Value
Unknown

CVE-2022-34000

Disclosure Date: June 19, 2022 (last updated February 23, 2025)
libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.
Attacker Value
Unknown

CVE-2021-45024

Disclosure Date: June 17, 2022 (last updated February 23, 2025)
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
Attacker Value
Unknown

CVE-2022-22317

Disclosure Date: June 17, 2022 (last updated February 23, 2025)
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
Attacker Value
Unknown

CVE-2022-22318

Disclosure Date: June 17, 2022 (last updated February 23, 2025)
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Attacker Value
Unknown

CVE-2021-41411

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.