CVE-2022-29278 - How Faulty Pointer Checks in NvmExpressDxe Risk Both SMRAM and OS Memory
In this post, we’ll look closely at CVE-2022-29278, a significant firmware-level security hole discovered in the NvmExpressDxe driver. The flaw can
CVE-2022-3377 - Analyzing the FNT File Vulnerability in Horner Automation’s Cscape (RCE Risk Inside)
Horner Automation’s Cscape is an automation software suite commonly used for programming and configuring controllers in industrial environments. In late 2022, a significant vulnerability
CVE-2022-20947 - Crashing Cisco ASA and FTD via HostScan DAP Bug—Root Cause and Exploit Explained
On November 16, 2022, Cisco disclosed a critical vulnerability tracked as CVE-2022-20947, affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2022-45395 - Exploiting Jenkins CCCC Plugin with XXE Vulnerability
In late 2022, security researchers uncovered a concerning vulnerability — CVE-2022-45395 — in the Jenkins CCCC Plugin, version .6 and earlier. This flaw lets attackers
CVE-2022-45389 An missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs for an attacker-specified repository.
The issue is caused by a missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier. When installing this plugin, an attacker could
Episode
00:00:00
00:00:00