CVE-2022-22610 - How a Memory Corruption Bug in WebKit Put Apple Users at Risk
CVE-2022-22610 might not sound like a major headline, but for millions of Apple users, this security flaw had the potential to become a
CVE-2022-36944 Scala 2.13.x has a Java deserialization chain in its JAR file. This risk is only present when LazyList deserialization is present in an application.
This issue was fixed in 2.13.10 release. This issue was discovered by Sergey Kovalev from VSEPR team in Google.
JAR files are widely
CVE-2022-40194 An Unauthenticated SSI vulnerability in the WooCommerce plugin = 5.3.5.
An attacker can exploit the unauthenticated vulnerability to retrieve the customer’s email address and other personally identifiable information. Unauthenticated information disclosure vulnerabilities occur when
CVE-2022-39239 On-Demand image optimization for Netlify using ipx. Versions prior to 1.2.3 are vulnerable to brute force attacks that can bypass the source image domain allowlist.
If you are using custom domain mapping or a wildcard mapping, it may be necessary to clear the cache manually by regenerating the mapped subdirectory.
CVE-2022-40088 The vulnerable component was found to contain an XSS flaw, where users can inject malicious code.
An attacker can leverage this vulnerability to conduct XSS attacks against users of the site via client-side scripting languages such as JavaScript or Python.
Episode
00:00:00
00:00:00