‼ CVE-2021-25485 ‼
📖 Read
via "National Vulnerability Database".
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38923 ‼
📖 Read
via "National Vulnerability Database".
IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25495 ‼
📖 Read
via "National Vulnerability Database".
A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25482 ‼
📖 Read
via "National Vulnerability Database".
SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25486 ‼
📖 Read
via "National Vulnerability Database".
Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25492 ‼
📖 Read
via "National Vulnerability Database".
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25498 ‼
📖 Read
via "National Vulnerability Database".
A possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25475 ‼
📖 Read
via "National Vulnerability Database".
A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25477 ‼
📖 Read
via "National Vulnerability Database".
An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25467 ‼
📖 Read
via "National Vulnerability Database".
Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25474 ‼
📖 Read
via "National Vulnerability Database".
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25471 ‼
📖 Read
via "National Vulnerability Database".
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25483 ‼
📖 Read
via "National Vulnerability Database".
Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25472 ‼
📖 Read
via "National Vulnerability Database".
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-41126 ‼
📖 Read
via "National Vulnerability Database".
October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted may still be able to sign in to the backend using October CMS v2.0. The issue has been patched in v2.1.12 of the october/october package. There are no workarounds for this issue and all users should update.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29908 ‼
📖 Read
via "National Vulnerability Database".
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25478 ‼
📖 Read
via "National Vulnerability Database".
A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25481 ‼
📖 Read
via "National Vulnerability Database".
An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.📖 Read
via "National Vulnerability Database".
❌ VMware ESXi Servers Encrypted by Lightning-Fast Python Script ❌
📖 Read
via "Threat Post".
The little snippet of Python code strikes fast and nasty, taking less than three hours to complete a ransomware attack from initial breach to encryption.📖 Read
via "Threat Post".
Threat Post
VMware ESXi Servers Encrypted by Lightning-Fast Python Script
It's a little snippet of Python code – 6KB – that strikes fast and nasty, taking less than three hours to complete from initial breach to encryption.
🕴 Aerospace, Telecommunications Companies Victims of Stealthy Iranian Cyber-Espionage Campaign 🕴
📖 Read
via "Dark Reading".
Since at least 2018, "MalKamak" group has targeted firms in the Middle East, Russia, and other areas to steal sensitive data, security vendor says.📖 Read
via "Dark Reading".
Dark Reading
Aerospace, Telecommunications Companies Victims of Stealthy Iranian Cyber-Espionage Campaign
Since at least 2018, "MalKamak" group has targeted firms in the Middle East, Russia, and other areas to steal sensitive data, security vendor says.
🕴 MacOS Security: What Security Teams Should Know 🕴
📖 Read
via "Dark Reading".
As more macOS patches emerge and cybercriminals and nation-states take aim at the platform, experts discuss how macOS security has evolved and how businesses can protect employees.📖 Read
via "Dark Reading".
Dark Reading
MacOS Security: What Security Teams Should Know
As more macOS patches emerge and cybercriminals and nation-states take aim at the platform, experts discuss how macOS security has evolved and how businesses can protect employees.