
The ZING protocol allows arbitrary remote command execution with SUPER privileges. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.īlackberry - qnx_software_development_platformĪ remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.Īll versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.Ĭrocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.Īn issue was discovered in Digi TransPort DR64, SR44 VC74, and WR.

From version 2.16.0, this functionality has been completely removed. From log4j 2.15.0, this behavior has been disabled by default. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.Īpache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.Īmd - amd_generic_encapsulated_software_architecture

A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.
