πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-29739 β€Ό

IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38370 β€Ό

In Alpine through 2.24, untagged responses from an IMAP server are accepted before STARTTLS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38373 β€Ό

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22674 β€Ό

The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38365 β€Ό

Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a "Glowworm" attack.

πŸ“– Read

via "National Vulnerability Database".
❌ eCh0raix Ransomware Variant Targets QNAP, Synology NAS Devices ❌

Some bad actors are honing tools to go after small fry: This variant was refined to target not one, but two vendors’ devices that are common in SOHO setups.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-3692 β€Ό

yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32768 β€Ό

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site scripting. Corresponding rendering instructions via TypoScript functionality HTMLparser does not consider all potentially malicious HTML tag & attribute combinations per default. In default scenarios, a valid backend user account is needed to exploit this vulnerability. In case custom plugins used in the website frontend accept and reflect rich-text content submitted by users, no authentication is required. Update to TYPO3 versions 7.6.53 ELTS, 8.7.42 ELTS, 9.5.29, 10.4.19, 11.3.2 that fix the problem described.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23171 β€Ό

A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37367 β€Ό

CTparental before 4.45.07 is affected by a code execution vulnerability in the CTparental admin panel. Because The file "bl_categories_help.php" is vulnerable to directory traversal, an attacker can create a file that contains scripts and run arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25082 β€Ό

An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23172 β€Ό

A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37366 β€Ό

CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37365 β€Ό

CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37391 β€Ό

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21680 β€Ό

A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-33708 β€Ό

Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21697 β€Ό

A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21682 β€Ό

A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37390 β€Ό

A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37389 β€Ό

Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

πŸ“– Read

via "National Vulnerability Database".