πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38455 β€Ό

The affected productÒ€ℒs OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31682 β€Ό

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36357 β€Ό

An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uint16_t "year" value, resulting in a type mismatch that can truncate a higher integer value to a smaller one, and bypass a timestamp check. The fix is to use the right endian conversion function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41747 β€Ό

Cross-Site Scripting (XSS) vulnerability exists in Csdn APP 4.10.0, which can be exploited by attackers to obtain sensitive information such as user cookies.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38471 β€Ό

There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38457 β€Ό

The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.

πŸ“– Read

via "National Vulnerability Database".
❌ Cisco SD-WAN Security Bug Allows Root Code Execution ❌

The high-severity bug, tracked as CVE-2021-1529, is an OS command-injection flaw.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Node.js sandboxes are open to prototype pollution πŸ—“οΈ

Sandbox breakout can lead to remote code execution, researchers warn

πŸ“– Read

via "The Daily Swig".
πŸ›  Faraday 3.18.0 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2021-0702 β€Ό

In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore downgrade. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-193932765

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42540 β€Ό

The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0651 β€Ό

In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-67013844

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0706 β€Ό

In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-193444889

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-30359 β€Ό

The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90.08.7405 can start the installation repair and place a specially crafted binary in the repair folder, which runs with the admin privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0705 β€Ό

In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-185388103

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42539 β€Ό

The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0870 β€Ό

In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-192472262

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42538 β€Ό

The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0643 β€Ό

In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-183612370

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0652 β€Ό

In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185178568

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0708 β€Ό

In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-183262161

πŸ“– Read

via "National Vulnerability Database".