Show filters
1,078 Total Results
Displaying 141-150 of 1,078
Sort by:
Attacker Value
Unknown
CVE-2022-39236
Disclosure Date: September 28, 2022 (last updated February 24, 2025)
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This is patched in matrix-js-sdk v19.7.0. Redacting applicable events, waiting for the sync processor to store data, and restarting the client are possible workarounds. Alternatively, redacting the applicable events and clearing all storage will fix the further perceived issues. Downgrading to an unaffected version, noting that such a version may be subject to other vulnerabilities, will additionally resolve the issue.
0
Attacker Value
Unknown
CVE-2022-35624
Disclosure Date: August 15, 2022 (last updated February 24, 2025)
In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets with SegO > SegN
0
Attacker Value
Unknown
CVE-2022-35623
Disclosure Date: August 15, 2022 (last updated February 24, 2025)
In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth
0
Attacker Value
Unknown
CVE-2022-26437
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831.
0
Attacker Value
Unknown
CVE-2020-28435
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
0
Attacker Value
Unknown
CVE-2022-28809
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-28808
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-28807
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-31159
Disclosure Date: July 15, 2022 (last updated February 24, 2025)
The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` method in the AWS S3 TransferManager component of the AWS SDK for Java v1 prior to version 1.12.261. Applications using the SDK control the `destinationDirectory` argument, but S3 object keys are determined by the application that uploaded the objects. The `downloadDirectory` method allows the caller to pass a filesystem object in the object key but contained an issue in the validation logic for the key name. A knowledgeable actor could bypass the validation logic by including a UNIX double-dot in the bucket key. Under certain conditions, this could permit them to retrieve a directory from their S3 bucket that is one level up in the filesystem from their working directory. This issue’s scope is limited to directories whose name prefix matches the destinationDirectory. E.g. for destination directory`/tmp/foo`, the actor can cause a download…
0
Attacker Value
Unknown
CVE-2022-21166
Disclosure Date: June 15, 2022 (last updated February 23, 2025)
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
0