Show filters
252 Total Results
Displaying 101-110 of 252
Sort by:
Attacker Value
Unknown

CVE-2022-24952

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered remotely by an invalid sequence number and a local bug triggered by invalid input sent directly to the IPC socket.
Attacker Value
Unknown

CVE-2022-24951

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket, enabling access to Eternal Terminal clients which attempt to connect in the future.
Attacker Value
Unknown

CVE-2022-24950

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().
Attacker Value
Unknown

CVE-2022-24949

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a race condition, buffer overflow, and logic bug all in PipeSocketHandler::listen().
Attacker Value
Unknown

CVE-2022-31109

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a `Laminas\Diactoros\Uri` instance associated with the incoming server request modified to reflect values from `X-Forwarded-*` headers. Such changes can potentially lead to XSS attacks (if a fully-qualified URL is used in links) and/or URL poisoning. Since the `X-Forwarded-*` headers do have valid use cases, particularly in clustered environments using a load balancer, the library offers mitigation measures only in the v2 releases, as doing otherwise would break these use cases immediately. Users of v2 releases from 2.11.1 can provide an additional argument to `Laminas\Diactoros\ServerRequestFactory::fromGlobals()` in the form of a `Laminas\Diactoros\RequestFilter\RequestFilterInte…
Attacker Value
Unknown

CVE-2022-29965

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corresponding to different privilege levels. An attacker can easily reconstruct these passwords and thus gain access to privileged maintenance operations. NOTE: this is different from CVE-2014-2350.
Attacker Value
Unknown

CVE-2022-29964

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.
Attacker Value
Unknown

CVE-2022-29963

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.
Attacker Value
Unknown

CVE-2022-29962

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.
Attacker Value
Unknown

CVE-2022-29601

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.