Cybersecurity researchers have called attention to a new campaign that's actively exploiting a recently disclosed critical security flaw in Langflow to deliver the Flodrix botnet malware.
"Attackers use the vulnerability to execute downloader scripts on compromised Langflow servers, which in turn fetch and install the Flodrix malware," Trend Micro researchers Aliakbar Zahravi, Ahmed Mohamed
A vulnerability was found in libtiff 4.4.0rc1 and classified as problematic. This issue affects the function TIFFClose of the file tif_close.c. The manipulation leads to release of reference.
The identification of this vulnerability is CVE-2022-2521. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in libtiff 4.4.0rc1. Affected is the function rotateImage of the file tiffcrop.c. The manipulation leads to double free.
This vulnerability is traded as CVE-2022-2519. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in LibTIFF 4.4.0. It has been classified as critical. This affects the function tiffcp of the file tools/tiffcp.c of the component TIFF File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2022-4645. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2022-3970. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as problematic, has been found in LibTIFF 4.4.0. This issue affects some unknown processing of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2023-0799. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, was found in LibTIFF 4.4.0. Affected is the function tiffcrop of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2023-0800. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in LibTIFF 4.4.0. It has been classified as critical. This affects an unknown part of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2023-0803. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, was found in LibTIFF up to 4.5.0. Affected is the function processCropSelections of the file tools/tiffcrop.c of the component TIFF Image Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2022-48281. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic has been found in LibTIFF 4.4.0. This affects an unknown part of the file libtiff/tif_unix.c of the component TIFF File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2023-0797. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic was found in LibTIFF 4.4.0. This vulnerability affects unknown code of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2023-0798. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in LibTIFF 4.4.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2023-0795. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.