CVE-2022-41184
published 2022-10-11CVE-2022-41184: Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.54%
42.3th percentile
Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal_core | — | — |
| sap | 3d_visual_enterprise_author | — | — |
| sap_se | sap_3d_visual_enterprise_author | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv6.1MEDIUM
vendor_oracle6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-945x-wvmp-64hw: Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (
ghsa_unreviewed·2022-10-12
CVE-2022-41184 [HIGH] CWE-119 GHSA-945x-wvmp-64hw: Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (
Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.
OSV
jqueryui vulnerability
osv·2022-09-09·CVSS 6.1
CVE-2021-41184 jqueryui vulnerability
jqueryui vulnerability
It was discovered that jQuery UI did not properly validate the values from
untrusted sources. An attacker could use this vulnerability to cause a crash or
possibly execute arbitrary code. This issue affected only Ubuntu 18.04 ESM and
Ubuntu 20.4 ESM. (CVE-2021-41184)
It was discovered that jQuery UI checkboxradio widget did not properly decode
certain values from HTML entities. An attacker could possibly use this issue to
generate a cross-site scripting(XSS) attack, resulting in a crash or possibly
execute arbitrary code. (CVE-2022-31160)
Oracle
Oracle Oracle Communications Risk Matrix: Management (jQueryUI) — CVE-2021-41184
vendor_oracle·2022-10-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Communications Risk Matrix: Management (jQueryUI) — CVE-2021-41184
Oracle Oracle Communications Risk Matrix: Management (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (jQueryUI) — CVE-2021-41184
vendor_oracle·2022-07-15·CVSS 5.4
CVE-2021-41184 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express (jQueryUI) — CVE-2021-41184
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Dashboard (jQueryUI) — CVE-2021-41184
vendor_oracle·2022-04-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Communications Risk Matrix: Dashboard (jQueryUI) — CVE-2021-41184
Oracle Oracle Communications Risk Matrix: Dashboard (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2022-001
vendor_drupal·2022-01-19·CVSS 6.5
CVE-2021-41184 [MEDIUM] Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2022-001
Title: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2022-001
Vulnerability Type: Cross Site Scripting
Description: jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issue that may affect Drupal 9 and 7: CVE-2021-41184: XSS in the `of` option of the `.position()` util It is possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release applies the fix for the above cross-site description issue, without making any of the other changes to the jQuery version that is included
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published