πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-21579 β€Ό

Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36763 β€Ό

In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32017 β€Ό

An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the listing of the content of the remote file system. This can be used to identify the complete server filesystem structure, i.e., identifying all the directories and files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21577 β€Ό

Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victimÒ€ℒs browser by tricking a victim in to following a specially crafted link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31503 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IGS files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12690.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21581 β€Ό

Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victimÒ€ℒs browser by tricking a victim in to following a specially crafted link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31504 β€Ό

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12691.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37558 β€Ό

A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a valid Knowledge Base URL is configured on the Knowledge Base configuration page and points to a MediaWiki instance. This relates to the proxy feature in class/centreon-knowledge/ProceduresProxy.class.php and include/configuration/configKnowledge/proxy/proxy.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33485 β€Ό

CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37557 β€Ό

A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21580 β€Ό

Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.

πŸ“– Read

via "National Vulnerability Database".
❌ Ransomware Volumes Hit Record Highs as 2021 Wears On ❌

The second quarter of the year saw the highest volumes of ransomware attacks ever, with Ryuk leading the way.

πŸ“– Read

via "Threat Post".
❌ Iranian APT Lures Defense Contractor in Catfishing-Malware Scam ❌

Fake aerobics-instructor profile delivers malware in a supply-chain attack attempt from TA456.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-30571 β€Ό

Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30589 β€Ό

Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30569 β€Ό

Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30581 β€Ό

Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30576 β€Ό

Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30582 β€Ό

Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30573 β€Ό

Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30588 β€Ό

Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".