CPE
UNC3569 Exploitation of Sogou Input Method to Deploy GRAYRABBIT Backdoor
1 rule 4 TTPs 1 CVE 6 IOCsUNC3569 exploited a command-line argument injection flaw in Sogou Input Method to trigger an insecure Chromium component and execute the GRAYRABBIT backdoor.
Expat XML Parsing Library Integer Overflow Vulnerabilities
1 TTP 2 CVEsThe Expat XML parsing library is affected by integer overflow vulnerabilities (CVE-2022-25235, CVE-2022-25236) that can be exploited by a local attacker to achieve arbitrary code execution or denial of service.
Vulnerabilities in Nokogiri Vendored libxml2 and libxslt Libraries
3 CVEsNokogiri versions prior to 1.13.2 bundle vulnerable libxml2 2.9.12 and libxslt 1.1.34 libraries, exposing applications to denial of service, memory disclosure, and potential code execution.
HAProxy CVE-2021-40346 Integer Overflow Leading to HTTP Request Smuggling and ACL Bypass
2 TTPs 1 CVEA critical integer overflow vulnerability, CVE-2021-40346, in HAProxy's `htx_add_header()` function allows unauthenticated attackers to bypass access control rules by crafting HTTP requests with specific header name lengths, leading to HTTP request smuggling and unauthorized access to backend paths, for which a public exploit is available.