Show filters
321 Total Results
Displaying 111-120 of 321
Sort by:
Attacker Value
Unknown
CVE-2022-1742
Disclosure Date: June 24, 2022 (last updated February 24, 2025)
The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an attacker to directly access the operating system. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.
0
Attacker Value
Unknown
CVE-2022-1741
Disclosure Date: June 24, 2022 (last updated February 24, 2025)
The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or install malicious code.
0
Attacker Value
Unknown
CVE-2022-1740
Disclosure Date: June 24, 2022 (last updated February 24, 2025)
The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export, and application export functionality rely on self-attestation mechanisms. An attacker could leverage this vulnerability to disguise malicious applications on a device.
0
Attacker Value
Unknown
CVE-2022-1739
Disclosure Date: June 24, 2022 (last updated February 24, 2025)
The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable against, a cryptographic key provided by the manufacturer to detect tampering. An attacker could leverage this vulnerability to install malicious code, which could also be spread to other vulnerable ImageCast X devices via removable media.
0
Attacker Value
Unknown
CVE-2022-31028
Disclosure Date: June 07, 2022 (last updated February 23, 2025)
MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing the connections. Public-facing MinIO deployments are most affected. Users should upgrade to RELEASE.2022-06-02T02-11-04Z to receive a patch. One possible workaround is to use a reverse proxy to limit the number of connections being attempted in front of MinIO, and actively rejecting connections from such malicious clients.
0
Attacker Value
Unknown
CVE-2021-42860
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification
0
Attacker Value
Unknown
CVE-2021-42859
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release
0
Attacker Value
Unknown
CVE-2022-29320
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
0
Attacker Value
Unknown
CVE-2022-1560
Disclosure Date: May 16, 2022 (last updated February 23, 2025)
The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link
0
Attacker Value
Unknown
CVE-2022-1027
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.
0