Meta tags:
description= Securing the world s software, together.;
Headings (most frequently used words):
vulnerabilities, we, ve, disclosed, before, march, 2020, disclosure, policy, product, platform, support, company,
Text of the page (most frequently used words):
the (137), cve (123), discovered (92), published (89), ago (89), 2019 (68), years (66), vulnerability (39), attacker (38), denial (36), service (36), 2018 (35), can (34), code (32), kevin (32), backhouse (32), overflow (31), crafted (30), and (29), when (29), file (27), user (26), arbitrary (26), apache (25), allows (23), year (23), remote (22), man (22), yue (22), this (21), via (21), server (18), 2017 (17), due (17), prototype (17), rce (16), before (16), kernel (16), apple (16), package (16), read (15), memory (15), cause (15), data (15), execute (14), buffer (14), integer (14), exiv2 (14), could (13), execution (13), malicious (13), files (13), deserialization (12), which (12), http (12), npm (12), crash (12), ghostscript (12), heap (12), image (12), disclosure (11), attackers (11), use (11), object (11), api (10), that (10), affected (10), ignite (10), leading (10), using (9), they (9), into (9), information (9), stack (9), extend (9), pollution (9), format (9), github (8), corruption (8), with (8), xml (8), because (8), properties (8), apport (8), antonio (8), 2020 (8), security (7), specially (7), from (7), vulnerable (7), access (7), local (7), process (7), rest (7), type (7), external (7), trigger (7), xnu (7), etherpad (7), lite (7), inject (7), geode (7), for (7), libav (7), through (7), reading (7), vulnerabilities (7), spark (6), unsafe (6), struts (6), spring (6), may (6), attack (6), restlet (6), xxe (6), parameter (6), running (6), function (6), certain (6), packet (6), rsyslog (6), exploited (6), tricked (6), adding (6), modifying (6), asger (6), feldthaus (6), cristian (6), alexandru (6), staicu (6), injection (6), path (6), pdf (6), loop (6), sscanf (6), large (6), png (6), out (6), bounds (6), lab (5), issue (5), versions (5), able (5), not (5), request (5), entities (5), are (5), class (5), has (5), possibly (5), privileged (5), mangler (5), classes (5), unprivileged (5), based (5), control (5), commands (5), cpu (5), subtitle (5), decoder (5), video (5), matroska (5), libavcodec (5), srtdec (5), ffmpeg (5), ubuntu (5), policy (4), microsoft (4), edge (4), exploit (4), page (4), context (4), attacks (4), scripting (4), application (4), run (4), swagger (4), possible (4), deserialized (4), amqp (4), range (4), camel (4), name (4), xss (4), link (4), was (4), objects (4), classpath (4), port (4), checking (4), overflows (4), nfs (4), then (4), call (4), corrupt (4), gain (4), pid (4), merge (4), caused (4), value (4), processing (4), very (4), ansible (4), hog (4), close (4), scanning (4), htmlsubtitles (4), facebook (4), allocation (4), sigsegv (4), crw (4), ssh (4), whoopsie (4), nico (4), waisman (4), agustin (4), gianni (4), bftpd (4), disclosures (4), web (3), allow (3), will (3), engine (3), launcher (3), makes (3), potentially (3), any (3), does (3), parser (3), org (3), enable (3), affects (3), entity (3), parsing (3), more (3), red (3), hat (3), who (3), castor (3), component (3), untrusted (3), hadoop (3), cluster (3), used (3), client (3), infinispan (3), products (3), macos (3), app (3), present (3), contains (3), one (3), com (3), way (3), current (3), rights (3), nick (3), rolfe (3), controls (3), command (3), defaults (3), deep (3), handling (3), icecast (3), media (3), cached (3), opened (3), processed (3), even (3), sandbox (3), mode (3), dsafer (3), option (3), confusion (3), artifex (3), opening (3), just (3), node (3), infinite (3), thereby (3), module (3), sparql (3), vivo (3), traversal (3), srt_to_ass (3), complex (3), argument (3), fizz (3), null (3), connecting (3), php (3), scrypt_enc (3), dumps (3), enables (3), including (3), after (3), contrib (3), march (3), projects (3), settings (2), 2021 (2), about (2), resources (2), our (2), view (2), logged (2), browser (2), all (2), its (2), socket (2), machine (2), would (2), shell (2), snakeyaml (2), library (2), yaml (2), specification (2), plugin (2), payload (2), message (2), unsafely (2), string (2), patch (2), requests (2), java (2), framework (2), expansion (2), only (2), other (2), jboss (2), manager (2), dtrace (2), address (2), within (2), space (2), deserializing (2), lead (2), mapreduce (2), job (2), history (2), configuration (2), containing (2), sensitive (2), host (2), fail (2), rfd (2), 6835 (2), location (2), cache (2), ios (2), tvos (2), watchos (2), involves (2), serialized (2), tcpserver (2), locator (2), network (2), librelp (2), bas (2), van (2), schaik (2), serialization (2), party (2), sending (2), endpoints (2), memcached (2), endpoint (2), vpn (2), underflow (2), strongswan (2), batik (2), exists (2), chakra (2), successfully (2), pavel (2), avgustinov (2), gridclientjdkmarshaller (2), instead (2), libnmap (2), morgan (2), lodash (2), headers (2), craft (2), relative (2), insufficient (2), mpath (2), enabled (2), kill (2), vitro (2), uri (2), fetch (2), publish (2), airsonic (2), misuses (2), strstr (2), quadratic (2), tag (2), snprintf (2), inner (2), brace (2), open (2), source (2), pointer (2), dereference (2), webp (2), pngimage (2), readmetadata (2), mishandles (2), iccoffset (2), assertion (2), failure (2), std (2), bad_alloc (2), exception (2), parameters (2), during (2), key (2), libssh2 (2), leads (2), time (2), toctou (2), report (2), schismtracker (2), nps (2), 14438 (2), uboot (2), multiple (2), free (2), pmcisconames (2), pmdb2diag (2), pmaixforwardedfrom (2), symlink (2), race (2), aslr (2), offsets (2), hotspot (2), oob (2), proftpd (2), prior (2), advisories (2), those (2), teams (2), dec (2), cookie, privacy, terms, inc, shop, press, careers, blog, company, contact, status, learning, professional, services, community, forum, help, support, desktop, electron, atom, partners, developer, platform, pricing, customer, stories, enterprise, features, product, prone, enticing, unsuspecting, currently, failed, conditions, 0141, performs, received, applications, launched, programmatically, account, ran, affect, apps, submit, aditya, sharad, 12612, generator, openapi, specifications, written, invoke, insecurely, parse, codegen, 1000208, 1000207, uses, xstreamhandler, instance, xstream, deserialize, without, applying, filtering, provide, 9805, pivotal, springframework, core, being, converted, 8045, submitted, servers, backed, json, 8046, simplexmlprovider, jax, extension, 14868, conducts, general, properly, considered, related, xmlrepresentation, domrepresentation, saxrepresentation, jacksonrepresentation, 14949, xmlutils, jbpmmigration, performed, while, flaw, accessible, perform, advanced, 7545, business, gives, ability, 32gb, 13782, exposure, flaws, 12634, unmarshalling, operation, expose, private, owned, construct, directives, reference, 15713, release, sanitize, jsonp, callback, bypass, intended, restrictions, making, reflected, download, pad, editor, cross, site, maliciously, released, 6834, window, href, hotrod, authenticated, attain, conduct, further, 15089, 13904, stores, form, operations, invocations, these, write, 15693, opens, deserializes, gains, 15692, version, earlier, x509, certificates, peer, result, 1000140, jonas, jensen, 4160, 4136, negative, diskless, boot, mechanism, have, list, allowed, 3rd, some, components, discovery, spi, persistence, steamer, 1295, credentials, normal, group, root, 5388, charon, subclasses, abstractdocument, takes, inputstream, arg, constructor, fixed, calling, newinstance, 8013, pktmnglr_ipfilter_input, 4249, handles, such, same, administrative, take, system, install, programs, change, delete, create, new, accounts, full, 8294, nodes, 8018, under, common, configurations, compute, namespace, evaluate, input, ognl, 11776, 16492, 16460, 16486, recursive, 16469, field, scan, 16461, 5413, mac, attempts, mount, share, 4291, 4288, 4287, 4286, 4259, functions, mergewith, defaultsdeep, 16487, 4407, icmp, streaming, copies, preparing, send, authentication, special, xiph, 18820, boths, deploy, thus, overwrite, 16472, 19134, 19475, 19477, 19476, property, set, 16490, 16489, 16491, remotely, preventing, device, accessing, internet, hogging, cores, 4460, itself, usage, exec, third, 5414, regular, expression, redos, demonstrated, filter, 20regex, individual, project, 6986, copying, overwriting, outside, specified, destination, controller, restricting, absolute, 3828, permissions, manage, podcasts, hosting, streamer, uploading, podcast, 20222, 9720, 9719, handle_open_brace, 9721, ff_htmlmarkup_to_ass, 9718, 9717, unauthenticated, triggering, tls, 3560, cpp, returning, response, lacks, character, 13114, webpimage, decodechunks, followed, long, 13111, chunklength, subtraction, 13109, zero, 13108, ciffdirectory, readdirectory, 13110, invalid, 13113, pngchunk, parsechunkcontent, uncontrolled, 13112, uncaught, achieving, there, risk, exploitation, side, pass, hhvm, robert, marsh, 3570, diffie, hellman, exchange, 13115, 4gb, daemon, reports, belonging, users, 11476, check, trick, contents, 7307, privilege, escalation, reporter, 14523, amiga, oktalyzer, 14524, mtm, 15119, permission, problems, videolan, vlc, 14970, 14777, 14779, 14778, 14776, 14533, 14534, 14535, 14498, 14437, das, fermin, serna, 14204, 14203, 14202, 14201, 14200, 14199, 14198, 14197, 14196, 14195, 14194, 14193, 14192, 15026, linux, 16234, 16233, 16232, 16231, 16230, deref, alloc_workqueue, google, chromium, 5876, session, 17042, 17040, 17041, openmpt, libopenmpt, 17113, potential, modplug_samplename, modplug_instrumentname, disconnect, 17498, bson_ensure_space, bson, 613, subsequent, 11484, reads, config, 11481, recycling, generate, 15790, rabbitmq, 18609, amqp_handle_input, vbscript, viewer, once, clicks, pannellum, max, schaefer, 16763, pure, ftpd, 20176, exhaustion, listdir, dos, 6162, btfdp, uninitialized, hidegroups_init, int, bool, casting, 9272, getstateflags, 9273, pools, transfer, 123, cves, lists, recent, please, visit, researchers, find, widely, coordinate, here, been, announced, development, patches, available, see, disclosed, events, get, involved, research, codeql, bounties, back, works, best, javascript, wayback, archive, 20210126052825, https, securitylab, timestamps, capture, success, 2022, feb, jan, 2026, 108, captures,
Text of the page (random words):
usion vulnerability in ghostscript when opening or processing ps and pdf files cve 2018 19476 cve 2018 19477 artifex ghostscript published 2 years ago discovered by man yue mo using a specially crafted ps or pdf file an attacker can corrupt memory when the file is opened or processed by ghostscript this is caused by insufficient type checking leading to type confusion which could potentially be exploited to execute code even when ghostscript is running in sandbox mode using the dsafer option rce vulnerability in ghostscript when opening or processing ps and pdf files cve 2018 19475 artifex ghostscript published 2 years ago discovered by man yue mo using a specially crafted ps or pdf file an attacker can execute arbitrary shell commands when the file is opened or processed by ghostscript even when ghostscript is running in sandbox mode using the dsafer option rce vulnerability in ghostscript when opening or processing ps and pdf files cve 2018 19134 artifex ghostscript published 2 years ago discovered by man yue mo using a specially crafted ps or pdf file an attacker can execute arbitrary code when the file is opened or processed by ghostscript even when ghostscript is running in sandbox mode using the dsafer option this is caused by insufficient type checking leading to type confusion and memory corruption which can be exploited to execute code prototype pollution in cached path relative package cve 2018 16472 npm cached path relative published 2 years ago discovered by cristian alexandru staicu if an attacker control boths the path and the cached value they can deploy a prototype pollution attack and thus overwrite arbitrary properties on object prototype rce vulnerability in icecast server cve 2018 18820 xiph icecast published 2 years ago discovered by nick rolfe a remote code execution vulnerability exists in the way the icecast streaming media server copies http headers from a user request when preparing a request to send to an authentication server the vulnerability could allow an attacker to craft special http headers that corrupt memory and execute arbitrary code on the server kernel crash caused by buffer overflow in apple s icmp packet handling code cve 2018 4407 apple xnu kernel published 2 years ago discovered by kevin backhouse prototype pollution in lodash package cve 2018 16487 npm lodash published 2 years ago discovered by asger feldthaus the functions merge mergewith and defaultsdeep can be tricked into adding or modifying properties of the object prototype kernel rce caused by buffer overflows in macos nfs client cve 2018 4259 cve 2018 4286 cve 2018 4287 cve 2018 4288 cve 2018 4291 apple xnu kernel published 2 years ago discovered by kevin backhouse a malicious nfs server can trigger a buffer overflow in the kernel when a mac attempts to mount the nfs share code injection vulnerability in morgan package cve 2019 5413 npm morgan published 2 years ago discovered by cristian alexandru staicu an attacker can use the format parameter to inject arbitrary commands command injection in libnmap package cve 2018 16461 npm libnmap published 2 years ago discovered by cristian alexandru staicu if an attacker controls the range field for the network scan they can inject arbitrary os commands instead of an ip range prototype pollution in merge package cve 2018 16469 npm merge published 2 years ago discovered by asger feldthaus the merge recursive function can be tricked into adding or modifying properties of the object prototype prototype pollution in defaults deep package cve 2018 16486 npm defaults deep published 2 years ago discovered by asger feldthaus the defaults deep package can be tricked into adding or modifying properties of the object prototype command injection in ps package cve 2018 16460 npm ps published 2 years ago discovered by cristian alexandru staicu if an attacker controls the pid parameter they can inject arbitrary os commands instead of a process id prototype pollution in extend package cve 2018 16492 npm extend published 2 years ago discovered by asger feldthaus the extend package can be tricked into adding or modifying properties of the object prototype rce vulnerability in apache struts cve 2018 11776 apache struts published 2 years ago discovered by man yue mo under certain common configurations to compute the namespace struts will evaluate untrusted user input as ognl which allows for an attacker to execute arbitrary code rce in apache ignite via gridclientjdkmarshaller cve 2018 8018 apache ignite published 3 years ago discovered by man yue mo an attacker can execute arbitrary code on ignite nodes via the gridclientjdkmarshaller deserialization endpoint when the ignite classpath contains vulnerable classes chakra scripting engine memory corruption vulnerability cve 2018 8294 microsoft edge browser published 3 years ago discovered by pavel avgustinov nick rolfe a remote code execution vulnerability exists in the way that the chakra scripting engine handles objects in memory in microsoft edge the vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user an attacker who successfully exploited the vulnerability could gain the same user rights as the current user if the current user is logged on with administrative user rights an attacker who successfully exploited the vulnerability could take control of an affected system an attacker could then install programs view change or delete data or create new accounts with full user rights rce in apple s packet mangler cve 2018 4249 apple xnu kernel published 3 years ago discovered by kevin backhouse an issue was discovered in certain apple products ios before 11 4 is affected macos before 10 13 5 is affected tvos before 11 4 is affected watchos before 4 3 1 is affected the issue involves pktmnglr_ipfilter_input in com apple packet mangler in the kernel component it allows attackers to execute arbitrary code in a privileged context or cause a denial of service integer overflow and stack based buffer overflow via a crafted app apache batik information disclosure vulnerability cve 2018 8013 apache batik published 3 years ago discovered by man yue mo when deserializing subclasses of abstractdocument the class takes a string from the inputstream as the class name this name is then used to call the no arg constructor of the class this vulnerability was fixed by checking the class type before calling newinstance in deserialization buffer underflow vulnerability in strongswan vpn charon server cve 2018 5388 strongswan published 3 years ago discovered by kevin backhouse a remote attacker with local user credentials possibly a normal user in the vpn group or root may be able to underflow the buffer and cause a denial of service possible rce in apache ignite deserialization endpoints cve 2018 1295 apache ignite published 3 years ago discovered by man yue mo the apache ignite serialization mechanism does not have a list of classes allowed for serialization deserialization which makes it possible to run arbitrary code when 3rd party vulnerable classes are present in the ignite classpath an attacker can exploit the vulnerability by sending a specially crafted serialized object to one of the deserialization endpoints of some ignite components discovery spi ignite persistence memcached endpoint and socket steamer negative integer overflows in apple s nfs diskless boot cve 2018 4136 cve 2018 4160 apple xnu kernel published 3 years ago discovered by jonas jensen stack buffer overflow in rsyslog librelp cve 2018 1000140 rsyslog published 3 years ago discovered by bas van schaik kevin backhouse rsyslog librelp version 1 2 14 and earlier contains a buffer overflow vulnerability in the checking of x509 certificates from a peer that can result in remote code execution rce in apache geode due unsafe deserialization in tcpserver cve 2017 15692 apache geode published 3 years ago discovered by man yue mo the tcpserver within the geode locator opens a network port that deserializes data if an unprivileged user gains access to the geode locator they may be able to cause remote code execution if certain classes are present on the classpath rce in apache geode due to unsafe deserialization of application objects cve 2017 15693 apache geode published 3 years ago discovered by man yue mo the geode server stores application objects in serialized form certain cluster operations and api invocations cause these objects to be deserialized an user with data write access to the cluster may be able to cause remote code execution if certain classes are present on the classpath rce in apple s packet mangler cve 2017 13904 apple xnu kernel published 3 years ago discovered by kevin backhouse an issue was discovered in certain apple products ios before 11 2 is affected macos before 10 13 2 is affected tvos before 11 2 is affected watchos before 4 2 is affected the issue involves the kernel component it allows attackers to execute arbitrary code in a privileged context or cause a denial of service memory corruption via a crafted app unsafe deserialization in infinispan cve 2017 15089 red hat infinispan published 3 years ago discovered by man yue mo the hotrod client in infinispan would unsafely read deserialized data on information from the cache an authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client and possibly conduct further attacks xss in etherpad lite before v1 6 3 via window location href cve 2018 6834 etherpad lite published 3 years ago discovered by man yue mo a page in the pad editor of etherpad lite is vulnerable to cross site scripting xss attack via a maliciously crafted link this affects all versions of etherpad lite before v1 6 3 was released rfd vulnerability in etherpad lite s http api cve 2018 6835 etherpad lite published 3 years ago discovered by man yue mo versions of etherpad lite before the release of v1 16 3 fail to sanitize the name of the jsonp callback function used in the http api this allows remote attackers to bypass intended access restrictions making the http api vulnerable to a reflected file download rfd attack xxe vulnerability in apache hadoop cve 2017 15713 apache hadoop published 3 years ago discovered by man yue mo this vulnerability in apache hadoop allows a cluster user to expose private files owned by the user running the mapreduce job history server process the malicious user can construct a configuration file containing xml directives that reference sensitive files on the mapreduce job history server host apache camel s castor unmarshalling operation is vulnerable to rce attacks cve 2017 12634 apache camel castor published 3 years ago discovered by man yue mo apache camel s camel castor component has a java object deserialization vulnerability deserializing untrusted data can lead to security flaws memory exposure vulnerability in dtrace cve 2017 13782 apple xnu kernel published 3 years ago discovered by kevin backhouse this vulnerability gives a local attacker who can trigger dtrace to run the ability to read any memory address within a 32gb range of the kernel s address space xxe vulnerability in jboss business process manager cve 2017 7545 red hat jboss process manager published 3 years ago discovered by man yue mo the xmlutils class in jbpmmigration performed expansion of external parameter entities while parsing xml files a remote attacker could use this flaw to read files accessible to the user running the application server and potentially perform other more advanced xml external entity xxe attacks parameter entity xxe vulnerability in restlet cve 2017 14949 restlet published 3 years ago discovered by man yue mo restlet framework before 2 3 12 allows remote attackers to access arbitrary files via a crafted rest api http request that conducts an xxe attack because only general external entities not parameter external entities are properly considered this is related to xmlrepresentation domrepresentation saxrepresentation and jacksonrepresentation xml external entity expansion vulnerability in restlet cve 2017 14868 restlet published 3 years ago discovered by man yue mo restlet framework before 2 3 11 when using simplexmlprovider allows remote attackers to access arbitrary files via an xxe attack in a rest api http request this affects use of the jax rs extension rce in patch requests in spring data rest cve 2017 8046 spring data rest published 3 years ago discovered by man yue mo malicious patch requests submitted to servers using spring data rest backed http resources can use specially crafted json data to run arbitrary java code rce vulnerability in spring amqp cve 2017 8045 spring amqp published 3 years ago discovered by man yue mo in pivotal spring amqp versions before 1 7 4 1 6 11 and 1 5 7 an org springframework amqp core message may be unsafely deserialized when being converted into a string a malicious payload could be crafted to exploit this and enable a remote code execution attack rce vulnerability in the apache struts rest plugin cve 2017 9805 apache struts published 3 years ago discovered by man yue mo in vulnerable versions of apache struts the rest plugin uses an xstreamhandler with an instance of xstream to deserialize data without applying any type filtering this makes it possible to provide an xml payload that will allow remote code execution rce when it is deserialized arbitrary code execution via swagger yaml parser cve 2017 1000207 cve 2017 1000208 swagger codegen and parser published 4 years ago discovered by man yue mo the swagger code generator and parser use the snakeyaml library to process openapi swagger specifications written in yaml they invoke snakeyaml insecurely which allows an attacker to parse a malicious specification and execute arbitrary code unsafe deserialization in apache spark launcher api cve 2017 12612 apache spark published 4 years ago discovered by aditya sharad in all versions of apache spark from 1 16 0 to 2 1 1 the launcher api performs unsafe deserialization of data received by its socket this makes applications launched programmatically using the launcher api potentially vulnerable to arbitrary code execution by an attacker with access to any user account on the local machine the attacker would be able to execute code as the user that ran the spark application it does not affect apps run by spark submit or spark shell scripting engine remote memory corruption vulnerability cve 2017 0141 microsoft edge browser published 4 years ago discovered by kevin backhouse microsoft edge is prone to a remote memory corruption vulnerability attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page this could allow the attacker to execute arbitrary code in the context of the currently logged in user failed attacks will cause denial of service conditions disclosure policy read our disclosure policy product features security enterp...
|