โผ CVE-2020-5805 โผ
๐ Read
via "National Vulnerability Database".
In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-1061 โผ
๐ Read
via "National Vulnerability Database".
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27260 โผ
๐ Read
via "National Vulnerability Database".
Innokas Yhtymรยค Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcode reader to inject HL7 v2.x segments into specific HL7 v2.x messages via multiple expected parameters.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-4666 โผ
๐ Read
via "National Vulnerability Database".
IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186281.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-1063 โผ
๐ Read
via "National Vulnerability Database".
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may lead to a buffer overread, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).๐ Read
via "National Vulnerability Database".
โผ CVE-2021-1062 โผ
๐ Read
via "National Vulnerability Database".
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).๐ Read
via "National Vulnerability Database".
โผ CVE-2020-4606 โผ
๐ Read
via "National Vulnerability Database".
IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 184883.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-4667 โผ
๐ Read
via "National Vulnerability Database".
IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive information due to improper input validation. IBM X-Force ID: 186282.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-4664 โผ
๐ Read
via "National Vulnerability Database".
IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186235.๐ Read
via "National Vulnerability Database".
๐ฆฟ How to use Dropbox Passwords as your password manager ๐ฆฟ
๐ Read
via "Tech Republic".
Dropbox now offers its own password manager. Here are the steps on how to set it up and use it.๐ Read
via "Tech Republic".
TechRepublic
How to use Dropbox Passwords as your password manager
Dropbox now offers its own password manager. Here are the steps on how to set it up and use it.
โผ CVE-2020-17502 โผ
๐ Read
via "National Vulnerability Database".
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-26664 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-35131 โผ
๐ Read
via "National Vulnerability Database".
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-17504 โผ
๐ Read
via "National Vulnerability Database".
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in ngpsystemcmd.php in which the http parameters "x_modules" and "y_modules" are not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-17503 โผ
๐ Read
via "National Vulnerability Database".
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameter "locking" is not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-25678 โผ
๐ Read
via "National Vulnerability Database".
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-28208 โผ
๐ Read
via "National Vulnerability Database".
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.7.1.๐ Read
via "National Vulnerability Database".
๐ฆฟ How to use Dropbox Vault to secure sensitive files ๐ฆฟ
๐ Read
via "Tech Republic".
You can protect your online files by placing them in a virtual vault secured by a PIN.๐ Read
via "Tech Republic".
TechRepublic
How to use Dropbox Vault to secure sensitive files
You can protect your online files by placing them in a virtual vault secured by a PIN.
โ Ryuk Rakes in $150M in Ransom Payments โ
๐ Read
via "Threat Post".
An examination of the malware gang's payments reveals insights into its economic operations.๐ Read
via "Threat Post".
Threat Post
Ryuk Rakes in $150M in Ransom Payments
An examination of the malware gang's payments reveals insights into its economic operations.
โ A Look Ahead at 2021: SolarWinds Fallout and Shifting CISO Budgets โ
๐ Read
via "Threat Post".
Threatpost editors discuss the SolarWinds hack, healthcare ransomware attacks and other threats that will plague enterprises in 2021.๐ Read
via "Threat Post".
Threat Post
A Look Ahead at 2021: SolarWinds Fallout and Shifting CISO Budgets
Threatpost editors discuss the SolarWinds hack, healthcare ransomware attacks and other threats that will plague enterprises in 2021.
โผ CVE-2021-21116 โผ
๐ Read
via "National Vulnerability Database".
Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.๐ Read
via "National Vulnerability Database".