โผ CVE-2020-14410 โผ
๐ Read
via "National Vulnerability Database".
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.๐ Read
via "National Vulnerability Database".
โ DNSpooq Flaws Allow DNS Hijacking of Millions of Devices โ
๐ Read
via "Threat Post".
Seven flaws in open-source software Dnsmasq could allow DNS cache poisoning attacks and remote code execution.๐ Read
via "Threat Post".
Threat Post
DNSpooq Flaws Allow DNS Hijacking of Millions of Devices
Seven flaws in open-source software Dnsmasq could allow DNS cache poisoning attacks and remote code execution.
๐ด SolarWinds Attack Underscores 'New Dimension' in Cyber-Espionage Tactics ๐ด
๐ Read
via "Dark Reading".
Meanwhile, Malwarebytes is the latest victim, Symantec discovers a fourth piece of malware used in the massive attack campaign, and FireEye Mandiant releases a free tool to help spot signs of the attack.๐ Read
via "Dark Reading".
Dark Reading
SolarWinds Attack Underscores 'New Dimension' in Cyber-Espionage Tactics
Meanwhile, Malwarebytes is the latest victim, Symantec discovers a fourth piece of malware used in the massive attack campaign, and FireEye Mandiant releases a free tool to help spot signs of the attack.
๐ด Microsoft to Launch 'Enforcement Mode' for Zerologon Flaw ๐ด
๐ Read
via "Dark Reading".
Enforcement mode for the Netlogon Domain Controller will be enabled by default with the Feb. 9 security update.๐ Read
via "Dark Reading".
Darkreading
Microsoft to Launch 'Enforcement Mode' for Zerologon Flaw
Enforcement mode for the Netlogon Domain Controller will be enabled by default with the Feb. 9 security update.
๐ฆฟ The aftermath of the SolarWinds breach: Organizations need to be more vigilant ๐ฆฟ
๐ Read
via "Tech Republic".
Security experts say organizations are, and should, implement a number of changes ranging from how they vet vendors to handling application updates.๐ Read
via "Tech Republic".
TechRepublic
The aftermath of the SolarWinds breach: Organizations need to be more vigilant
Security experts say organizations are, and should, implement a number of changes ranging from how they vet vendors to handling application updates.
๐ด Vulnerabilities in Popular DNS Software Allow Poisoning ๐ด
๐ Read
via "Dark Reading".
Seven flaws in DNSMasq have limited impact, but in combination they could be chained to create a multistaged attack.๐ Read
via "Dark Reading".
Dark Reading
Vulnerabilities in Popular DNS Software Allow Poisoning
Seven flaws in DNSMasq have limited impact, but in combination they could be chained to create a multistaged attack.
โผ CVE-2020-27264 โผ
๐ Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticated, physically proximate attackers to brute-force the keys via Bluetooth Low Energy.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-29598 โผ
๐ Read
via "National Vulnerability Database".
The My AIA SG application 1.2.6 for Android allows attackers to obtain user credentials via logcat because of excessive logging.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27269 โผ
๐ Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physically proximate attackers to replay communication sequences via Bluetooth Low Energy.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27256 โผ
๐ Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin therapy settings.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-11997 โผ
๐ Read
via "National Vulnerability Database".
Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27266 โผ
๐ Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27268 โผ
๐ Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass checks for default PINs via Bluetooth Low Energy.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27258 โผ
๐ Read
via "National Vulnerability Database".
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pumpรขโฌโขs keypad lock PIN via Bluetooth Low Energy.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-28707 โผ
๐ Read
via "National Vulnerability Database".
The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() event is not validated. The stockdio_eventer function listens for any postMessage event. After a message event is sent to the application, this function sets the "e" variable as the event and checks that the types of the data and data.method are not undefined (empty) before proceeding to eval the data.method received from the postMessage. However, on a different website. JavaScript code can call window.open for the vulnerable WordPress instance and do a postMessage(msg,'*') for that object.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19362 โผ
๐ Read
via "National Vulnerability Database".
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-13134 โผ
๐ Read
via "National Vulnerability Database".
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27851 โผ
๐ Read
via "National Vulnerability Database".
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).๐ Read
via "National Vulnerability Database".
โผ CVE-2020-27850 โผ
๐ Read
via "National Vulnerability Database".
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19363 โผ
๐ Read
via "National Vulnerability Database".
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-3137 โผ
๐ Read
via "National Vulnerability Database".
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.๐ Read
via "National Vulnerability Database".