CVE-2022-28766 The Zoom Client for Meetings and Room before 5.12.6 are vulnerable to DLL injection.
The target user must have installed the Zoom client on their system and logged in to the system as a user with an elevated privileges.
CVE-2022-38165 Arbitrary write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with contents in arbitrary locations on F-Secure Policy Manager Server.
This may lead to a situation where the file becomes susceptible to being overwritten by a malicious user or script, causing a potential data loss
CVE-2022-44001 An issue was discovered in BACKCLICK Professional 5.9.63
A remote attacker could use a forged message to access the CORBA service and thus take control of the application. This update fixes the issue
CVE-2021-33897 - Buffer Overflow and Improper Path Handling in Synthesia – Easy App Crash Exploit
Disclosure Timeline
References:
- CVE-2021-33897 NVD Entry
- Synthesia Official Site
Introduction
Synthesia is a popular educational music application for learning and playing MIDI songs,
CVE-2022-42733 - Exploiting the syngo Dynamics Web Service File Read Vulnerability
CVE-2022-42733 is a security flaw found in all versions of syngo Dynamics before VA40G HF01. This vulnerability can allow attackers to read files
Episode
00:00:00
00:00:00