🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2020-29259 ‼

Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject parameter to feedback.php.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17092 ‼

, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-16971 ‼

, aka 'Azure SDK for Java Security Feature Bypass Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-16958 ‼

, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16959, CVE-2020-16960, CVE-2020-16961, CVE-2020-16962, CVE-2020-16963, CVE-2020-16964.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-7339 ‼

Use of a Broken or Risky Cryptographic Algorithm vulnerability in McAfee Database Security Server and Sensor prior to 4.8.0 in the form of a SHA1 signed certificate that would allow an attacker on the same local network to potentially intercept communication between the Server and Sensors.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17159 ‼

, aka 'Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17119 ‼

, aka 'Microsoft Outlook Information Disclosure Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17133 ‼

, aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17099 ‼

, aka 'Windows Lock Screen Security Feature Bypass Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-29259 ‼

Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject parameter to feedback.php.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17092 ‼

, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-16971 ‼

, aka 'Azure SDK for Java Security Feature Bypass Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-16958 ‼

, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16959, CVE-2020-16960, CVE-2020-16961, CVE-2020-16962, CVE-2020-16963, CVE-2020-16964.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-7339 ‼

Use of a Broken or Risky Cryptographic Algorithm vulnerability in McAfee Database Security Server and Sensor prior to 4.8.0 in the form of a SHA1 signed certificate that would allow an attacker on the same local network to potentially intercept communication between the Server and Sensors.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17159 ‼

, aka 'Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17119 ‼

, aka 'Microsoft Outlook Information Disclosure Vulnerability'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-17133 ‼

, aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-2493 ‼

This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-2491 ‼

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-2497 ‼

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-2494 ‼

This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later

📖 Read

via "National Vulnerability Database".