CVE-2022-0096 An attacker in Google Chrome before 97.0.4692.71 could exploit heap corruption after an AOF.
CVE Solution: Update to version 97.0.4689 or newer. An issue was discovered in certain configurations of Google Chrome prior to version 97.0.
CVE-2022-0557 OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
It has been fixed in version 1.2.12. In older versions, attackers could inject an arbitrary command as GET or POST request parameter by
CVE-2022-23773 Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags as tags.
An example of this happening is if there is a feature called “vX.Y.Z” and there was a branch called “vX.Y”. An actor
CVE-2022-23806 The Curve.IsOnCurve function in Go before 1.16.14 and 1.17.x can return true when a big.Int value is not a valid field element.
This could cause the software to appear vulnerable when it is not. Users should upgrade to the latest version of Go.
In the past, when
CVE-2022-0018 An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app which sends the credentials of the local user account to the GlobalProtect portal when the Single Sign-On feature is enabled.
where the local user accounts are shared across different applications, such as email. Remote attackers can use this information exposure vulnerability to impersonate the local
Episode
00:00:00
00:00:00