Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2022
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
CVSS Score
4.4
EPSS Score
0.0
Published
2022-09-21
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
CVSS Score
5.3
EPSS Score
0.004
Published
2022-09-21
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
CVSS Score
5.5
EPSS Score
0.004
Published
2022-09-21
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-09-21
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CVSS Score
7.5
EPSS Score
0.006
Published
2022-09-21
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CVSS Score
7.5
EPSS Score
0.007
Published
2022-09-21
By sending specific queries to the resolver, an attacker can cause named to crash.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-09-21
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
CVSS Score
3.7
EPSS Score
0.001
Published
2022-09-21
The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.
CVSS Score
9.4
EPSS Score
0.001
Published
2022-09-21
mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
CVSS Score
7.0
EPSS Score
0.0
Published
2022-09-21


Contact Us

Shodan ® - All rights reserved