Security Vulnerabilities
- CVEs Published In February 2022
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
Windows Common Log File System Driver Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Named Pipe File System Elevation of Privilege Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Microsoft Office Information Disclosure Vulnerability