Comunidad Pen7esting
3.58K subscribers
510 photos
40 videos
142 files
5.08K links
Download Telegram
National Vulnerability Database
CVE-2020-9968

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.7, tvOS 14.0, watchOS 7.0. A malicious application may be able to access restricted files.
Vulnerabilidades en Magento: ejecución de código arbitrario, SQL injection y otras
https://blog.segu-info.com.ar/2020/10/vulnerabilidades-en-magento-ejecucion.html
Major Vulnerabilities Discovered in Qualcomm QCMAP (Qualcomm Mobile Access Point)
(CVE-2020-25858, CVE-2020-3657, CVE-2020-25859)
https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities
Nuevo método de ataque a certificados TLS, denominado Raccoon attacK
https://t.co/T62CnoTmNR— Fran Andrades (@AndradesFran) September 10, 2020
National Vulnerability Database
CVE-2020-5791

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.
Adobe lanza un parche para solventar vulnerabilidades críticas de 10 programas

Dentro de las afectadas tenemos a Photoshop, Illustrator, InDesign, Marketo, After Effects, Animate, Premiere Pro, Media Encoder, Creative Cloud y Dreamweaver tanto en MacOS como en Windows.

Cada herramienta tenía distintas vulnerabilidades, Illustrator por ejemplo recibió un total de 7 fixes entre los que prevenían ejecución de código remoto.

#Adobe

Fuente en inglés:
https://www.zdnet.com/article/adobe-releases-another-out-of-band-patch-to-squash-critical-bugs-across-creative-software/
National Vulnerability Database
CVE-2020-5977

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
GravityRAT: spyware con módulos para MacOS y Android
https://blog.segu-info.com.ar/2020/10/gravityrat-spyware-con-modulos-para.html