CVE-2022-40977 - Understanding the Pilz PASvisu Server Path Traversal (“Zip-Slip”) Vulnerability – Technical Analysis & Exploit Example
In September 2022, a significant security bug, CVE-2022-40977, was discovered in the Pilz PASvisu Server (before version 1.12.). This flaw enables attackers
CVE-2022-44749 - How a KNIME Zip-Slip Flaw Can Overwrite Anything On Your PC
If you use the popular data tool KNIME Analytics Platform, you might have opened a workflow downloaded from the internet. What if simply opening such
CVE-2022-45868 - H2 Database Engine Cleartext Password on Command Line (DISPUTED)
In 2022, a security concern was raised regarding how H2 Database Engine, up to version 2.1.214, allows users to start its web-based
CVE-2022-41924 - How a Tailscale Windows Client Vulnerability Allowed Malicious Websites to Remotely Execute Code
In late 2022, a critical security vulnerability was identified in the Tailscale Windows client. Now tracked as CVE-2022-41924, this flaw allowed a malicious
CVE-2022-36337 - Stack Buffer Overflow in Insyde InsydeH2O (Kernel 5.–5.5) and How It Can Lead to Code Execution
In 2022, security researchers found a critical buffer overflow vulnerability in the InsydeH2O UEFI firmware (specifically versions with kernel 5. through 5.5). This issue,
Episode
00:00:00
00:00:00