ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-44451
+1 in the same advisory: …44452
Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability.

Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21897.

NVD description · AI analysis pending
7.82%
  • linuxmint xreader
CVE-2023-29380
Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.

Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.

NVD description · AI analysis pending
7.52% PoC
  • linuxmint warpinator
CVE-2022-42725
Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.

Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.

NVD description · AI analysis pending
7.51% PoC
  • linuxmint warpinator
CVE-2019-20326
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

NVD description · AI analysis pending
7.82% PoC
  • gnome gthumb
  • gnome pix
  • gnome debian linux
CVE-2019-17080
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs.

mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.

NVD description · AI analysis pending
7.88% PoC ×3
  • linuxmint mintinstall
CVE-2018-13054
An issue was discovered in Cinnamon 1.9.2 through 3.8.6.

An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.

NVD description · AI analysis pending
8.12%
  • debian debian linux
  • debian cinnamon