🛡 Cybersecurity & Privacy 🛡 - News
26K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2020-16126 ‼

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-16127 ‼

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17053 ‼

, aka 'Internet Explorer Memory Corruption Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17019 ‼

, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17064, CVE-2020-17065, CVE-2020-17066.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17055 ‼

, aka 'Windows Remote Access Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17071 ‼

, aka 'Windows Delivery Optimization Information Disclosure Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17070 ‼

, aka 'Windows Update Medic Service Elevation of Privilege Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17106 ‼

, aka 'HEVC Video Extensions Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17107, CVE-2020-17108, CVE-2020-17109, CVE-2020-17110.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17040 ‼

, aka 'Windows Hyper-V Security Feature Bypass Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17012 ‼

, aka 'Windows Bind Filter Driver Elevation of Privilege Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-7328 ‼

External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO administrator.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17018 ‼

, aka 'Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17021.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17020 ‼

, aka 'Microsoft Word Security Feature Bypass Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17057 ‼

, aka 'Windows Win32k Elevation of Privilege Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17064 ‼

, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17019, CVE-2020-17065, CVE-2020-17066.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17102 ‼

, aka 'WebP Image Extensions Information Disclosure Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17058 ‼

, aka 'Microsoft Browser Memory Corruption Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-16994 ‼

, aka 'Azure Sphere Unsigned Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16970, CVE-2020-16982, CVE-2020-16984, CVE-2020-16987, CVE-2020-16991.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17000 ‼

, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17021 ‼

, aka 'Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17085 ‼

, aka 'Microsoft Exchange Server Denial of Service Vulnerability'.

📖 Read

via "National Vulnerability Database".