NVD disclosure day

Published threat advisories for August 10, 2022

CVE advisoryCRITICAL

CVE-2021-33643

libtar Crafted Tar File Out-of-Bounds Read Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in libtar that allows an attacker to trigger an out-of-bounds read by submitting a crafted tar file with a zero-size header. This could potentially impact system stability or lead to further security risks if the affected technology is used to process untrusted tar files.

CVE advisoryKnown Exploit

CVE-2022-0028

PAN-OS URL Filtering Policy Misconfiguration Allows Denial-of-Service Attacks.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A misconfiguration in PAN-OS URL filtering policies allows network attackers to conduct denial-of-service attacks, appearing to originate from Palo Alto Networks firewalls. This could obscure attacker identity and implicate the firewall, impacting service availability but not data confidentiality or integrity. Realisti

• CISA KEV