πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-33794 β€Ό

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-32440 β€Ό

The Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-21359 β€Ό

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2017-16632 β€Ό

In SapphireIMS 4097_1, the password in the database is stored in Base64 format.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37699 β€Ό

Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used when pages/_error.js was statically generated allowing an open redirect to occur to an external site. In general, this redirect does not directly harm users although can allow for phishing attacks by redirecting to an attacker's domain from a trusted domain. We recommend everyone to upgrade regardless of whether you can reproduce the issue or not. The issue has been patched in release 11.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38592 β€Ό

Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38591 β€Ό

An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38593 β€Ό

Qt 5.0.0 through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37222 β€Ό

Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-24576 β€Ό

Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Warns: Another Unpatched PrintNightmare Zero-Day ❌

The out-of-band warning pairs with a working proof-of-concept exploit for the issue, circulating since mid-July.

πŸ“– Read

via "Threat Post".
❌ QR Code Scammers Get Creative with Bitcoin ATMs ❌

Threat actors are targeting everyone from job hunters to Bitcoin traders to college students wanting a break on their student loans, by exploiting the popular technology's trust relationship with users.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep45: Routers attacked, hacking tool hacked, and betrayers betrayed [Podcast] ⚠

Latest episode - listen now! (And learn about the Navajo Nation's selfless cryptographic contribution to America.)

πŸ“– Read

via "Naked Security".
β€Ό CVE-2020-28165 β€Ό

The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.

πŸ“– Read

via "National Vulnerability Database".
🦿 Microsoft fixes Print Spooler bugs with August Patch Tuesday rollout 🦿

The fix, though, means that only administrators will be able to install print drivers on Windows PCs.

πŸ“– Read

via "Tech Republic".
🦿 When 2FA on your Linux servers won't let you in, try this fix 🦿

When your Linux servers are giving you fits, Jack Wallen has the solution for you.

πŸ“– Read

via "Tech Republic".
❌ Ransomware Payments Explode Amid β€˜Quadruple Extortion’ ❌

Unit 42 puts the average payout at over half a million, while Barracuda has tracked a 64 percent year over year spike in the number of attacks.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-27792 β€Ό

The command Ò€œipfilterҀ� in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-27794 β€Ό

A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35955 β€Ό

Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20314 β€Ό

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.

πŸ“– Read

via "National Vulnerability Database".