πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-0627 β€Ό

In OMA DRM, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722434; Issue ID: ALPS05722434.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-37702 β€Ό

Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0417 β€Ό

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336702.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0416 β€Ό

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336700.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0626 β€Ό

In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687510; Issue ID: ALPS05687510.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-18746 β€Ό

SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21867 β€Ό

A unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0420 β€Ό

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381065.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0418 β€Ό

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336706.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21868 β€Ό

A unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0628 β€Ό

In OMA DRM, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722454; Issue ID: ALPS05722454.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-21781 β€Ό

An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a processÒ€ℒs memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38710 β€Ό

Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0407 β€Ό

In clk driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05479659; Issue ID: ALPS05479659.

πŸ“– Read

via "National Vulnerability Database".
🦿 The top 3 cryptocurrency scams of 2021 🦿

Kaspersky says that fake exchanges, fake mining hardware and wallet phishing are the most popular crypto scams of the year, many of which it said have a higher-than-usual level of detail.

πŸ“– Read

via "Tech Republic".
⚠ Video surveillance network hacked by researchers to hijack footage ⚠

Home automation. Internet of Things. Cloud management. And a security bug that could let other people watch you online...

πŸ“– Read

via "Naked Security".
❌ T-Mobile: >40 Million Customers’ Data Stolen ❌

Attackers stole tens of millions of current, former or prospective customers' personal data, the company confirmed. It's providing 2 years of free ID protection.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-23425 β€Ό

All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39283 β€Ό

liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-23069 β€Ό

Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28146 β€Ό

Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

πŸ“– Read

via "National Vulnerability Database".