π¦Ώ Excel is still a security headache after 30 years because of this one feature π¦Ώ
π Read
via "Tech Republic".
Threat researcher explains why it's tricky to tell the difference between legitimate Excel Macros and ones that deliver malware.π Read
via "Tech Republic".
TechRepublic
Excel is still a security headache after 30 years because of this one feature
Threat researcher explains why it's tricky to tell the difference between legitimate Excel Macros and ones that deliver malware.
π¦Ώ A diverse cybersecurity team can help alleviate the talent shortage π¦Ώ
π Read
via "Tech Republic".
Responsibilities are complex and require different job descriptions, reduced bias and a variety of skill sets, industry leaders say.π Read
via "Tech Republic".
TechRepublic
A diverse cybersecurity team can help alleviate the talent shortage
Responsibilities are complex and require different job descriptions, reduced bias and a variety of skill sets, industry leaders say.
π¦Ώ How to install Webmin on Rocky Linux π¦Ώ
π Read
via "Tech Republic".
With Webmin, you can better secure and manage your instances of Rocky Linux. Jack Wallen walks you through the process of getting this web-based tool up and running.π Read
via "Tech Republic".
TechRepublic
How to install Webmin on Rocky Linux
With Webmin, you can better secure and manage your instances of Rocky Linux. Jack Wallen walks you through the process of getting this web-based tool up and running.
βΌ CVE-2021-38553 βΌ
π Read
via "National Vulnerability Database".
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36787 βΌ
π Read
via "National Vulnerability Database".
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.π Read
via "National Vulnerability Database".
βΌ CVE-2021-34823 βΌ
π Read
via "National Vulnerability Database".
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP request to the server, it triggers a code path that will download a configuration file from a specified remote machine over HTTP. There is an XXE flaw in processing of this configuration file that allows reading local (to macOS) files and uploading them to remote machines.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32071 βΌ
π Read
via "National Vulnerability Database".
The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control. A successful exploit could allow an attacker to view and modify application data, and cause a denial of service for users.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36793 βΌ
π Read
via "National Vulnerability Database".
The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37028 βΌ
π Read
via "National Vulnerability Database".
There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is disabled by default, attackers with administrator privilege could execute part of commands.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36785 βΌ
π Read
via "National Vulnerability Database".
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32068 βΌ
π Read
via "National Vulnerability Database".
The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack by sending multiple session renegotiation requests, due to insufficient TLS session controls. A successful exploit could allow an attacker to modify application data and state.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36792 βΌ
π Read
via "National Vulnerability Database".
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38302 βΌ
π Read
via "National Vulnerability Database".
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38554 βΌ
π Read
via "National Vulnerability Database".
HashiCorp Vault and Vault EnterpriseΓ’β¬β’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.π Read
via "National Vulnerability Database".
βΌ CVE-2020-18759 βΌ
π Read
via "National Vulnerability Database".
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32069 βΌ
π Read
via "National Vulnerability Database".
The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation. A successful exploit could allow an attacker to view and modify data.π Read
via "National Vulnerability Database".
βΌ CVE-2020-18757 βΌ
π Read
via "National Vulnerability Database".
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36790 βΌ
π Read
via "National Vulnerability Database".
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36788 βΌ
π Read
via "National Vulnerability Database".
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36791 βΌ
π Read
via "National Vulnerability Database".
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37586 βΌ
π Read
via "National Vulnerability Database".
The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Administrator rights) to replay a previously recorded conversation of another tenant due to insufficient validation.π Read
via "National Vulnerability Database".