πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Test πŸ•΄

A security researcher explains the dangers of poor visibility in the cloud and a new strategy to evaluate IAM exposure in Google Cloud Platform.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-28921 β€Ό

An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs). This could lead to arbitrary Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19873 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability than CVE-2019-16356 and CVE-2019-9983.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19874 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27746 β€Ό

Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15685 β€Ό

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27745 β€Ό

Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15684 β€Ό

Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7780 β€Ό

This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15680 β€Ό

In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15686 β€Ό

Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal usersÒ€ℒ cookies.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19877 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against AprolSqlServer, a different vulnerability than CVE-2019-16357.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19875 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnerability than CVE-2019-16364.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15681 β€Ό

In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28922 β€Ό

An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL functionality that allows low-privilege users to read and write arbitrary physical memory. This could lead to arbitrary Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25014 β€Ό

A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15682 β€Ό

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-15683 β€Ό

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-19876 β€Ό

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-10772 β€Ό

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25708 β€Ό

A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.

πŸ“– Read

via "National Vulnerability Database".