Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-27477 | 1 Bytecodealliance | 2 Cranelift-codegen, Wasmtime | 2023-03-15 | N/A | 4.3 MEDIUM |
wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than 16. There is an off-by-one error in the calculation of the mask to the `pshufb` instruction which causes incorrect results to be returned if lanes are selected from the second vector. This codegen bug has been fixed in Wasmtiem 6.0.1, 5.0.1, and 4.0.1. Users are recommended to upgrade to these updated versions. If upgrading is not an option for you at this time, you can avoid this miscompilation by disabling the Wasm simd proposal. Additionally the bug is only present on x86_64 hosts. Other platforms such as AArch64 and s390x are not affected. | |||||
CVE-2023-1287 | 1 3ds | 1 Enovia Live Collaboration | 2023-03-15 | N/A | 9.8 CRITICAL |
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. | |||||
CVE-2022-47471 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2023-03-15 | N/A | 5.5 MEDIUM |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | |||||
CVE-2022-47456 | 2 Google, Unisoc | 27 Android, S8000, S8000 Firmware and 24 more | 2023-03-15 | N/A | 5.5 MEDIUM |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. | |||||
CVE-2022-47461 | 2 Google, Unisoc | 27 Android, S8000, S8000 Firmware and 24 more | 2023-03-15 | N/A | 6.7 MEDIUM |
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. | |||||
CVE-2022-47460 | 2 Google, Unisoc | 27 Android, S8000, S8000 Firmware and 24 more | 2023-03-15 | N/A | 5.5 MEDIUM |
In gpu device, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel. | |||||
CVE-2022-47481 | 2 Google, Unisoc | 27 Android, S8000, S8000 Firmware and 24 more | 2023-03-15 | N/A | 5.5 MEDIUM |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. | |||||
CVE-2022-47480 | 2 Google, Unisoc | 27 Android, S8000, S8000 Firmware and 24 more | 2023-03-15 | N/A | 5.5 MEDIUM |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. | |||||
CVE-2022-47462 | 2 Google, Unisoc | 27 Android, S8000, S8000 Firmware and 24 more | 2023-03-15 | N/A | 6.7 MEDIUM |
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. | |||||
CVE-2023-27164 | 1 Halo | 1 Halo | 2023-03-15 | N/A | 4.8 MEDIUM |
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file. | |||||
CVE-2022-3381 | 1 Gitlab | 1 Gitlab | 2023-03-15 | N/A | 6.1 MEDIUM |
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites | |||||
CVE-2023-27119 | 1 Webassembly | 1 Webassembly | 2023-03-15 | N/A | 5.5 MEDIUM |
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild. | |||||
CVE-2023-1303 | 1 Ucms Project | 1 Ucms | 2023-03-15 | N/A | 9.8 CRITICAL |
A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the component System File Management Module. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-222683. | |||||
CVE-2022-3767 | 1 Gitlab | 1 Dynamic Application Security Testing Analyzer | 2023-03-15 | N/A | 6.5 MEDIUM |
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host. | |||||
CVE-2022-3758 | 1 Gitlab | 1 Gitlab | 2023-03-15 | N/A | 5.4 MEDIUM |
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet. | |||||
CVE-2023-0483 | 1 Gitlab | 1 Gitlab | 2023-03-15 | N/A | 3.8 LOW |
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site. | |||||
CVE-2022-4462 | 1 Gitlab | 1 Gitlab | 2023-03-15 | N/A | 4.3 MEDIUM |
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response. | |||||
CVE-2022-4317 | 1 Gitlab | 1 Dynamic Application Security Testing Analyzer | 2023-03-15 | N/A | 6.1 MEDIUM |
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects. | |||||
CVE-2023-25814 | 1 Metersphere | 1 Metersphere | 2023-03-15 | N/A | 6.5 MEDIUM |
metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to create a resource file through UI operations is able to append a path to their submission query which will be read by the system and displayed to the user. This allows a users of the system to read arbitrary files on the filesystem of the server so long as the server process itself has permission to read the requested files. This issue has been addressed in version 2.7.1. All users are advised to upgrade. There are no known workarounds for this issue. | |||||
CVE-2023-25573 | 1 Metersphere | 1 Metersphere | 2023-03-15 | N/A | 7.5 HIGH |
metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. |