🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2020-18773 ‼

An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.

? Read

via "National Vulnerability Database".
‼ CVE-2021-36013 ‼

Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

? Read

via "National Vulnerability Database".
‼ CVE-2021-28596 ‼

Adobe Framemaker version 2020.0.1 (and earlier) and 2019.0.8 (and earlier) are affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

? Read

via "National Vulnerability Database".
‼ CVE-2020-18776 ‼

In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.

? Read

via "National Vulnerability Database".
‼ CVE-2021-39614 ‼

D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values.

? Read

via "National Vulnerability Database".
‼ CVE-2020-18775 ‼

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.

? Read

via "National Vulnerability Database".
‼ CVE-2020-18774 ‼

A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.

? Read

via "National Vulnerability Database".
‼ CVE-2020-18771 ‼

Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.

? Read

via "National Vulnerability Database".
‼ CVE-2021-39602 ‼

A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a remote malicious user cause a Denial of Service.

? Read

via "National Vulnerability Database".
‼ CVE-2021-39613 ‼

** UNSUPPORTED WHEN ASSIGNED ** D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

? Read

via "National Vulnerability Database".
‼ CVE-2021-39599 ‼

Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in the (2) c parameter in admin.php.

? Read

via "National Vulnerability Database".
‼ CVE-2021-23431 ‼

The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-23406 ‼

This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-23429 ‼

All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-23432 ‼

This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-23430 ‼

All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.

📖 Read

via "National Vulnerability Database".
🦿 Microsoft Power Apps misconfiguration exposes data from 38 million records 🦿

The leaked data included personal information for COVID-19 contact tracing and vaccination appointments, social security numbers for job applicants, employee IDs, names and email addresses.

📖 Read

via "Tech Republic".
‼ CVE-2021-36385 ‼

A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-38613 ‼

The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-33191 ‼

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the application binary. This was addressed in version 0.10.0

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-39376 ‼

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.

📖 Read

via "National Vulnerability Database".