🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2021-1692 ‼

Hyper-V Denial of Service Vulnerability This CVE ID is unique from CVE-2021-1691.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-1718 ‼

Microsoft SharePoint Server Tampering Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-6709 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-1678 ‼

NTLM Security Feature Bypass Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-1645 ‼

Windows Docker Information Disclosure Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-1711 ‼

Microsoft Office Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-1652 ‼

Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-6660 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-6679 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-1714 ‼

Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1713.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-6711 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-6697 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-1716 ‼

Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1715.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-6721 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-6698 ‼

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

📖 Read

via "National Vulnerability Database".
🕴 More SolarWinds Attack Details Emerge 🕴

A third piece of malware is uncovered, but there's still plenty of unknowns about the epic attacks purportedly out of Russia.

📖 Read

via "Dark Reading".
‼ CVE-2021-23935 ‼

OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-23929 ‼

OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-23931 ‼

OX App Suite through 7.10.4 allows XSS via an inline binary file.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-15799 ‼

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-26995 ‼

A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of SGI and RGB files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.

📖 Read

via "National Vulnerability Database".