๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2020-4663 โ€ผ

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186234.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1058 โ€ผ

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1066 โ€ผ

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to unexpected consumption of resources, which in turn may lead to denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1057 โ€ผ

NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for which the guest is not authorized, which may lead to integrity and confidentiality loss, denial of service, or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1064 โ€ผ

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1060 โ€ผ

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1065 โ€ผ

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-3111 โ€ผ

The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-8584 โ€ผ

Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrary code execution.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-5805 โ€ผ

In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1061 โ€ผ

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-27260 โ€ผ

Innokas Yhtymรƒยค Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcode reader to inject HL7 v2.x segments into specific HL7 v2.x messages via multiple expected parameters.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-4666 โ€ผ

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186281.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1063 โ€ผ

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may lead to a buffer overread, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-1062 โ€ผ

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-4606 โ€ผ

IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 184883.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-4667 โ€ผ

IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive information due to improper input validation. IBM X-Force ID: 186282.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-4664 โ€ผ

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186235.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿฆฟ How to use Dropbox Passwords as your password manager ๐Ÿฆฟ

Dropbox now offers its own password manager. Here are the steps on how to set it up and use it.

๐Ÿ“– Read

via "Tech Republic".
โ€ผ CVE-2020-17502 โ€ผ

Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-26664 โ€ผ

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

๐Ÿ“– Read

via "National Vulnerability Database".