🕴 FCC Designates Huawei & ZTE as National Security Threats 🕴
📖 Read
via "Dark Reading: ".
Backdoors in 5G network equipment from these vendors could enable espionage and malicious activity, agency says.📖 Read
via "Dark Reading: ".
Dark Reading
FCC Designates Huawei & ZTE as National Security Threats
Backdoors in 5G network equipment from these vendors could enable espionage and malicious activity, agency says.
🕴 Ripple20 Threatens Increasingly Connected Medical Devices 🕴
📖 Read
via "Dark Reading: ".
A series of IoT vulnerabilities could put hospital networks, medical data, and patient safety at risk.📖 Read
via "Dark Reading: ".
Dark Reading
Ripple20 Threatens Increasingly Connected Medical Devices
A series of IoT vulnerabilities could put hospital networks, medical data, and patient safety at risk.
ATENTION‼ New - CVE-2019-20408
📖 Read
via "National Vulnerability Database".
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2020-10379
📖 Read
via "National Vulnerability Database".
In Pillow before 6.2.3 and 7.x before 7.0.1, there are two Buffer Overflows in libImaging/TiffDecode.c.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2020-10378
📖 Read
via "National Vulnerability Database".
In libImaging/PcxDecode.c in Pillow before 6.2.3 and 7.x before 7.0.1, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2020-10177
📖 Read
via "National Vulnerability Database".
Pillow before 6.2.3 and 7.x before 7.0.1 has multiple out-of-bounds reads in libImaging/FliDecode.c.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-20892
📖 Read
via "National Vulnerability Database".
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-19506
📖 Read
via "National Vulnerability Database".
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-19505
📖 Read
via "National Vulnerability Database".
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-16213
📖 Read
via "National Vulnerability Database".
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2018-21268
📖 Read
via "National Vulnerability Database".
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.📖 Read
via "National Vulnerability Database".
âš Firefox 78 is out – with a mysteriously empty list of security fixes âš
📖 Read
via "Naked Security".
TLS 1.0 and TLS 1.1 are now considered security risks and blocked by default.📖 Read
via "Naked Security".
Naked Security
Firefox 78 is out – with a mysteriously empty list of security fixes
TLS 1.0 and TLS 1.1 are now considered security risks and blocked by default.
ATENTION‼ New - CVE-2019-20408
📖 Read
via "National Vulnerability Database".
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.📖 Read
via "National Vulnerability Database".
âš Google stops pushing scam ads on Americans searching for how to vote âš
📖 Read
via "Naked Security".
No US entity charges citizens for registering to vote, but plenty of Google ads were happy to do so - and to grab your PII in the process.📖 Read
via "Naked Security".
Naked Security
Google stops pushing scam ads on Americans searching for how to vote
No US entity charges citizens for registering to vote, but plenty of Google ads were happy to do so – and to grab your PII in the process.
ATENTION‼ New - CVE-2020-10379
📖 Read
via "National Vulnerability Database".
In Pillow before 6.2.3 and 7.x before 7.0.1, there are two Buffer Overflows in libImaging/TiffDecode.c.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2020-10378
📖 Read
via "National Vulnerability Database".
In libImaging/PcxDecode.c in Pillow before 6.2.3 and 7.x before 7.0.1, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2020-10177
📖 Read
via "National Vulnerability Database".
Pillow before 6.2.3 and 7.x before 7.0.1 has multiple out-of-bounds reads in libImaging/FliDecode.c.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-20892
📖 Read
via "National Vulnerability Database".
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-19506
📖 Read
via "National Vulnerability Database".
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-19505
📖 Read
via "National Vulnerability Database".
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2019-16213
📖 Read
via "National Vulnerability Database".
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.📖 Read
via "National Vulnerability Database".