πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-35397 β€Ό

A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this vulnerability by sending crafted HTTP request with specific path to read. Successful exploitation could allow the attacker to read files that should be restricted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36483 β€Ό

DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37231 β€Ό

A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because of the missing boundary check.

πŸ“– Read

via "National Vulnerability Database".
❌ We COVID-Clicked on Garbage, Report Finds: Podcast ❌

Were we work-from-home clicking zombies? Steganography attacks snagged three out of eight recipients. Nasty CAPTCHAs suckered 50 times more clicks during 2020.

πŸ“– Read

via "Threat Post".
🦿 Global cyber intrusion activity jumped 125% in the first half of 2021 🦿

Companies in the U.S. were targeted more than those in any other country, according to Accenture's Cyber Incident Response Update.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-3680 β€Ό

showdoc is vulnerable to Missing Cryptographic Step

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33336 β€Ό

Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33339 β€Ό

Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Phishing Campaign Dangles SharePoint File-Shares ❌

Attackers spoof sender addresses to appear legitimate in a crafty campaign that can slip past numerous detections, Microsoft researchers have discovered.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2020-24822 β€Ό

A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33337 β€Ό

Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24826 β€Ό

A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24824 β€Ό

A global buffer overflow issue in the dwarf::line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24827 β€Ό

A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-29765 β€Ό

IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID: 202476.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32590 β€Ό

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35463 β€Ό

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24821 β€Ό

A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26098 β€Ό

An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-24010 β€Ό

Improper limitation of a pathname to a restricted directoryΓ‚ vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32594 β€Ό

An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper with the underlying system's files via the upload of specifically crafted files.

πŸ“– Read

via "National Vulnerability Database".