โผ CVE-2020-13544 โผ
๐ Read
via "National Vulnerability Database".
An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021รขโฌโขs TextMaker application. A specially crafted document can cause the document parser to sign-extend a length used to terminate a loop, which can later result in the loopรขโฌโขs index being used to write outside the bounds of a heap buffer during the reading of file data. An attacker can entice the victim to open a document to trigger this vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-13545 โผ
๐ Read
via "National Vulnerability Database".
An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021รขโฌโขs TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-36174 โผ
๐ Read
via "National Vulnerability Database".
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27285 โผ
๐ Read
via "National Vulnerability Database".
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-36172 โผ
๐ Read
via "National Vulnerability Database".
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-36175 โผ
๐ Read
via "National Vulnerability Database".
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-36173 โผ
๐ Read
via "National Vulnerability Database".
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-8160 โผ
๐ Read
via "National Vulnerability Database".
MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-36176 โผ
๐ Read
via "National Vulnerability Database".
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-36177 โผ
๐ Read
via "National Vulnerability Database".
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.๐ Read
via "National Vulnerability Database".
โผ CVE-2012-10001 โผ
๐ Read
via "National Vulnerability Database".
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-36171 โผ
๐ Read
via "National Vulnerability Database".
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27279 โผ
๐ Read
via "National Vulnerability Database".
A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build versions prior to 3119.001).๐ Read
via "National Vulnerability Database".
โ Zyxel hardcoded admin password found โ patch now! โ
๐ Read
via "Naked Security".
Hardcoded passwords are always wrong - they are equivalent to implanting a global backdoor and hoping no one will find it.๐ Read
via "Naked Security".
Naked Security
Zyxel hardcoded admin password found โ patch now!
Hardcoded passwords are always wrong โ they are equivalent to implanting a global backdoor and hoping no one will find it.
๐ฆฟ Linux: How to create a new user with admin privileges ๐ฆฟ
๐ Read
via "Tech Republic".
Adding a user with admin privileges on Linux is easier than you think. Jack Wallen shows you how.๐ Read
via "Tech Republic".
TechRepublic
How to create a new user with admin privileges on Linux
Adding a user with admin privileges on Linux is easier than you think. Jack Wallen shows you how.
๐ NSA Provides Direction on Eliminating Obsolete Encryptionn Protocols ๐
๐ Read
via "Digital Guardian".
Moving on from old, out-of-date encryption protocols can protect sensitive and valuable data from being accessed by adversaries, the NSA reiterated this week.๐ Read
via "Digital Guardian".
Digital Guardian
NSA Provides Direction on Eliminating Obsolete Encryptionn Protocols
Moving on from old, out-of-date encryption protocols can protect sensitive and valuable data from being accessed by adversaries, the NSA reiterated this week.
โผ CVE-2020-5105 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-5106 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.๐ Read
via "National Vulnerability Database".
โผ CVE-2019-16962 โผ
๐ Read
via "National Vulnerability Database".
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-5104 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-5102 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.๐ Read
via "National Vulnerability Database".