‼ CVE-2020-5955 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38497 ‼
📖 Read
via "National Vulnerability Database".
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-20706 ‼
📖 Read
via "National Vulnerability Database".
Improper input validation vulnerability in the WebManager CLUSTERPRO X 1.0 for Windows and later, EXPRESSCLUSTER X 1.0 for Windows and later allows attacker to remote file upload via network.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-39237 ‼
📖 Read
via "National Vulnerability Database".
Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-20703 ‼
📖 Read
via "National Vulnerability Database".
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 1.0 for Windows and later, EXPRESSCLUSTER X 1.0 for Windows and later allows attacker to remote code execution via a network.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38500 ‼
📖 Read
via "National Vulnerability Database".
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38491 ‼
📖 Read
via "National Vulnerability Database".
Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-20707 ‼
📖 Read
via "National Vulnerability Database".
Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 1.0 for Windows and later, EXPRESSCLUSTER X 1.0 for Windows and later allows attacker to read files upload via network..📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27820 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38499 ‼
📖 Read
via "National Vulnerability Database".
Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38494 ‼
📖 Read
via "National Vulnerability Database".
Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-20135 ‼
📖 Read
via "National Vulnerability Database".
Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. Tenable has included a fix for this issue in Nessus 10.0.0. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29991 ‼
📖 Read
via "National Vulnerability Database".
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-41036 ‼
📖 Read
via "National Vulnerability Database".
In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-20705 ‼
📖 Read
via "National Vulnerability Database".
Improper input validation vulnerability in the WebManager CLUSTERPRO X 1.0 for Windows and later, EXPRESSCLUSTER X 1.0 for Windows and later allows attacker to remote file upload via network.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38493 ‼
📖 Read
via "National Vulnerability Database".
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38502 ‼
📖 Read
via "National Vulnerability Database".
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen by the MITM. If an unprotected authentication method was configured, the MITM could obtain the authentication credentials, too. This vulnerability affects Thunderbird < 91.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-29993 ‼
📖 Read
via "National Vulnerability Database".
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-38492 ‼
📖 Read
via "National Vulnerability Database".
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.📖 Read
via "National Vulnerability Database".
🕴 Simulation Game Teaches Non-Security Staff How to Handle a Cyber Crisis 🕴
📖 Read
via "Dark Reading".
In this card-based game from Kaspersky, players work through a cyberattack scenario and learn how each decision they make has consequences.📖 Read
via "Dark Reading".
Dark Reading
Simulation Game Teaches Non-Security Staff How to Handle a Cyber Crisis
In this card-based game from Kaspersky, players work through a cyberattack scenario and learn how each decision they make has consequences.
‼ CVE-2021-40849 ‼
📖 Read
via "National Vulnerability Database".
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.📖 Read
via "National Vulnerability Database".