‼ CVE-2021-35946 ‼
📖 Read
via "National Vulnerability Database".
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32766 ‼
📖 Read
via "National Vulnerability Database".
Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. This is problematic in case the public link share has been created with "Upload Only" privileges. (aka "File Drop"). A link share recipient is not expected to see which folders or files exist in a "File Drop" share. Using this vulnerability an attacker is able to enumerate folders in such a share. Exploitation requires that the attacker has access to a valid affected "File Drop" link share. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.0.1. Users who are unable to upgrade are advised to disable the Nextcloud Text application in the app settings.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-19752 ‼
📖 Read
via "National Vulnerability Database".
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38706 ‼
📖 Read
via "National Vulnerability Database".
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38707 ‼
📖 Read
via "National Vulnerability Database".
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39503 ‼
📖 Read
via "National Vulnerability Database".
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-35948 ‼
📖 Read
via "National Vulnerability Database".
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-19751 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-37631 ‼
📖 Read
via "National Vulnerability Database".
Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck application didn't properly check membership of users in a Circle. This allowed other users in the instance to gain access to boards that have been shared with a Circle, even if the user was not a member of the circle. It is recommended that Nextcloud Deck is upgraded to 1.5.1, 1.4.4 or 1.2.9. If you are unable to update it is advised to disable the Deck plugin.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-37630 ‼
📖 Read
via "National Vulnerability Database".
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed any user to join any "Secret Circle" without approval by the Circle owner leaking private information. It is recommended that Nextcloud Circles is upgraded to 0.19.15, 0.20.11 or 0.21.4. There are no workarounds for this issue.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-32782 ‼
📖 Read
via "National Vulnerability Database".
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. It is recommended that the Nextcloud Circles application is upgraded to 0.21.3, 0.20.10 or 0.19.14 to resolve this issue. As a workaround users may use a browser that has support for Content-Security-Policy. A notable exemption is Internet Explorer which does not support CSP properly.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-37628 ‼
📖 Read
via "National Vulnerability Database".
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share. It is recommended that the Nextcloud Richdocuments is upgraded to 3.8.4 or 4.2.1. If upgrading is not possible then it is recommended to disable the Richdocuments application.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39194 ‼
📖 Read
via "National Vulnerability Database".
kaml is an open source implementation of the YAML format with support for kotlinx.serialization. In affected versions attackers that could provide arbitrary YAML input to an application that uses kaml could cause the application to endlessly loop while parsing the input. This could result in resource starvation and denial of service. This only affects applications that use polymorphic serialization with the default tagged polymorphism style. Applications using the property polymorphism style are not affected. YAML input for a polymorphic type that provided a tag but no value for the object would trigger the issue. Version 0.35.3 or later contain the fix for this issue.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38704 ‼
📖 Read
via "National Vulnerability Database".
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39500 ‼
📖 Read
via "National Vulnerability Database".
Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-19750 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38705 ‼
📖 Read
via "National Vulnerability Database".
ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account for the attacker.📖 Read
via "National Vulnerability Database".
❌ Ragnar Locker Gang Warns Victims Not to Call the FBI ❌
📖 Read
via "Threat Post".
Investigators/the FBI/ransomware negotiators just screw everything up, the ransomware gang said, threatening to publish files if victims look for help.📖 Read
via "Threat Post".
Threat Post
Ragnar Locker Gang Warns Victims Not to Call the FBI
Investigators/the FBI/ransomware negotiators just screw everything up, the ransomware gang said, threatening to publish files if victims look for help.
‼ CVE-2021-32801 ‼
📖 Read
via "National Vulnerability Database".
Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. If upgrading is not an option users are advised to disable system logging to resolve this issue until such time that an upgrade can be performed Note that ff you do not use the Encryption-at-Rest functionality of Nextcloud you are not affected by this bug.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-19767 ‼
📖 Read
via "National Vulnerability Database".
A lack of target address verification in the destroycontract() function of 0xRACER 1.0 allows attackers to steal tokens from victim users via a crafted script.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-19768 ‼
📖 Read
via "National Vulnerability Database".
A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from victim users via a crafted script.📖 Read
via "National Vulnerability Database".