Concrete CMS up to 8.5.5 Phar Deserialization is_dir deserialization

A vulnerability was found in Concrete CMS up to 8.5.5 (Content Management System) and classified as critical. Affected by this issue is the function is_dir of the component Phar Deserialization. Upgrading to version 8.5.6 eliminates this vulnerability. The upgrade is hosted for download at documentation.concretecms.org.

Common Vulnerabilityies and Exposures

Nitro Pro PDF Document use after free [CVE-2021-21796]

A vulnerability was found in Nitro Pro PDF (affected version not known) and classified as critical. Affected by this issue is an unknown code block of the component Document Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative […]

Nitro Pro PDF Document double free [CVE-2021-21797]

A vulnerability was found in Nitro Pro PDF (the affected version unknown). It has been classified as critical. This affects some unknown processing of the component Document Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.

GlassWire 2.1.167 code injection [CVE-2021-22961]

A vulnerability was found in GlassWire 2.1.167. It has been declared as critical. This vulnerability affects an unknown function. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.