This archive contains all of the 118 exploits added to Packet Storm in September, 2022.
e8769c7d7fbd55f5a041781a53024d1c91b5564634f5d62fd852af01b6828895
Ubuntu Security Notice 5650-1 - It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. It was discovered that the virtual terminal driver in the Linux kernel did not properly handle VGA console font changes, leading to an out-of-bounds write. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.
a632d5cd01e37da5d6b95bdc8fbe10f589561b1c98bfa15fbef375169d7f4e19
Ubuntu Security Notice 5648-1 - It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Duoming Zhou discovered that race conditions existed in the timer handling implementation of the Linux kernel's Rose X.25 protocol layer, resulting in use-after-free vulnerabilities. A local attacker could use this to cause a denial of service.
694947a97de47224c18315b0b897bc61af2cb457626d7aece0e9acce30f80ef1
ZKSecurity BIO version 3.0.5.0_R suffers from a privilege escalation vulnerability.
b6d43dcace9b3768b3e0de50fde36243efa24ef1737964b40fee68c99c229b39
ZKSecurity BIO version 4.1.2 suffers from a remote SQL injection vulnerability that can allow for remote code execution.
2f5ddba7cf7e3024ddc6ad5a39968b8c149a652831c65c828f1565ea29f0e84d
Centreon version 22.04.0 suffers from a persistent cross site scripting vulnerability.
69cf7baade94fd5e803782c07bbd53d7ff5f985beb2b08f0768155d0e8d0e38f
GuppY CMS version 6.00.10 suffers from an authenticated remote shell upload vulnerability.
7379f5703f8c8447e89b8393459ce54d04deb30eed715a6df6b281a1b380609b
Joomla MyMuse extension version 4.3.0 suffers from a remote SQL injection vulnerability.
5deedb4e9c6f4ba784330c0618c0b611b0d2f5c953c41021281d833c3fab451c
Joomla JS Jobs Pro extension version 1.3.6 suffers from a remote SQL injection vulnerability.
1660f7d887aa22210db0f906f32132f8374ecb3142a0efecf10ad4eff14b83fa
Joomla jMarket extension version 5.15 suffers from a cross site scripting vulnerability.
8da5768e7cb7b5cc942dd12baf6b03bdcf8be558191a68d4c29a450bdde8b5c9