βΌ CVE-2020-17527 βΌ
π Read
via "National Vulnerability Database".
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.π Read
via "National Vulnerability Database".
βΌ CVE-2020-23736 βΌ
π Read
via "National Vulnerability Database".
There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs to cause computer crashes (BSOD).π Read
via "National Vulnerability Database".
βΌ CVE-2020-29534 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request, causing execve() to incorrectly optimize unshare_fd(), aka CID-0f2122045b94.π Read
via "National Vulnerability Database".
βΌ CVE-2020-23740 βΌ
π Read
via "National Vulnerability Database".
In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to increase user privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2020-29529 βΌ
π Read
via "National Vulnerability Database".
HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving ../ and symlinks.π Read
via "National Vulnerability Database".
βΌ CVE-2020-23738 βΌ
π Read
via "National Vulnerability Database".
There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a constructed program to cause a computer crash (BSOD)π Read
via "National Vulnerability Database".
π¦Ώ Phishing campaign threatens coronavirus vaccine supply chain π¦Ώ
π Read
via "Tech Republic".
The emails impersonate a member company of the COVID-19 vaccine supply chain to harvest account credentials, says IBM Security X-Force.π Read
via "Tech Republic".
TechRepublic
Phishing campaign threatens coronavirus vaccine supply chain
The emails impersonate a member company of the COVID-19 vaccine supply chain to harvest account credentials, says IBM Security X-Force.
π΄ Common Container Manager Is Vulnerable to Dangerous Exploit π΄
π Read
via "Dark Reading".
Container manager vulnerability is one of several weaknesses and vulnerabilities recently disclosed for Docker.π Read
via "Dark Reading".
Dark Reading
Common Container Manager Is Vulnerable to Dangerous Exploit
Container manager vulnerability is one of several weaknesses and vulnerabilities recently disclosed for Docker.
β Kmart, Latest Victim of Egregor Ransomware β Report β
π Read
via "Threat Post".
The struggling retailer's back-end services have been impacted, according to a report, just in time for the holidays.π Read
via "Threat Post".
Threat Post
Kmart, Latest Victim of Egregor Ransomware β Report
The struggling retailerβs back-end services have been impacted, according to a report, just in time for the holidays.
π΄ TrickBot's New Tactic Threatens Firmware π΄
π Read
via "Dark Reading".
A newly discovered module checks machines for flaws in the UEFI/BIOS firmware so malware can evade detection and persist on a device.π Read
via "Dark Reading".
Dark Reading
TrickBot's New Tactic Threatens Firmware
A newly discovered module checks machines for flaws in the UEFI/BIOS firmware so malware can evade detection and persist on a device.
π΄ Researchers Discover New Obfuscation-As-a-Service Platform π΄
π Read
via "Dark Reading".
Researchers detail how a Android APK obfuscation service automates detection evasion for highly malicious apps.π Read
via "Dark Reading".
Dark Reading
Researchers Discover New Obfuscation-As-a-Service Platform
Researchers detail how a Android APK obfuscation service automates detection evasion for highly malicious apps.
βΌ CVE-2018-21270 βΌ
π Read
via "National Vulnerability Database".
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).π Read
via "National Vulnerability Database".
βΌ CVE-2020-26248 βΌ
π Read
via "National Vulnerability Database".
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.π Read
via "National Vulnerability Database".
π΄ Potential Nation-State Actor Targets COVID-19 Vaccine Supply Chain π΄
π Read
via "Dark Reading".
Companies involved in technologies for keeping vaccines cold enough for safe storage and transportation are being targeted in a sophisticated spear-phishing campaign, IBM says.π Read
via "Dark Reading".
Dark Reading
Potential Nation-State Actor Targets COVID-19 Vaccine Supply Chain
Companies involved in technologies for keeping vaccines cold enough for safe storage and transportation are being targeted in a sophisticated spear-phishing campaign, IBM says.
βΌ CVE-2020-16123 βΌ
π Read
via "National Vulnerability Database".
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to expose sensitive information. Fixed in 1:13.99.3-1ubuntu2, 1:13.99.2-1ubuntu2.1, 1:13.99.1-1ubuntu3.8, 1:11.1-1ubuntu7.11, and 1:8.0-0ubuntu3.15.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27348 βΌ
π Read
via "National Vulnerability Database".
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.π Read
via "National Vulnerability Database".
βΌ CVE-2020-29561 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exception.π Read
via "National Vulnerability Database".
βΌ CVE-2020-5675 βΌ
π Read
via "National Vulnerability Database".
Out-of-bounds read issue in GT21 model of GOT2000 series (GT2107-WTBD all versions, GT2107-WTSD all versions, GT2104-RTBD all versions, GT2104-PMBD all versions, and GT2103-PMBD all versions), GS21 model of GOT series (GS2110-WTBD all versions and GS2107-WTBD all versions), and Tension Controller LE7-40GU-L all versions allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted packet. As a result, deterioration of communication performance or a denial-of-service (DoS) condition of the TCP communication functions of the products may occur.π Read
via "National Vulnerability Database".
βΌ CVE-2020-29565 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.π Read
via "National Vulnerability Database".
βΌ CVE-2020-28916 βΌ
π Read
via "National Vulnerability Database".
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.π Read
via "National Vulnerability Database".
βΌ CVE-2020-29562 βΌ
π Read
via "National Vulnerability Database".
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.π Read
via "National Vulnerability Database".