βΌ CVE-2021-37025 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37024 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37006 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37017 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37007 βΌ
π Read
via "National Vulnerability Database".
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37026 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37031 βΌ
π Read
via "National Vulnerability Database".
There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.π Read
via "National Vulnerability Database".
βΌ CVE-2021-20601 βΌ
π Read
via "National Vulnerability Database".
Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions allows an remote unauthenticated attacker to write a value that exceeds the configured input range limit by sending a malicious packet to rewrite the device value. As a result, the system operation may be affected, such as malfunction.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37029 βΌ
π Read
via "National Vulnerability Database".
There is an Identity verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37102 βΌ
π Read
via "National Vulnerability Database".
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system. Affected product versions include: FusionCompute 6.0.0, 6.3.0, 6.3.1, 6.5.0, 6.5.1, 8.0.0.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37005 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-35052 βΌ
π Read
via "National Vulnerability Database".
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37022 βΌ
π Read
via "National Vulnerability Database".
There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.π Read
via "National Vulnerability Database".
ποΈ Microsoft unveils βSuper Duper Secure Modeβ in latest version of Edge ποΈ
π Read
via "The Daily Swig".
Browser goes further to protect against bugs by disabling JITπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Microsoft unveils βSuper Duper Secure Modeβ in latest version of Edge
Browser goes further to protect against bugs by disabling JIT
π΄ Holiday Scams Drive SMS Phishing Attacks π΄
π Read
via "Dark Reading".
Attackers typically target consumers with malicious text messages containing obfuscated links, but experts say businesses are threatened as well.π Read
via "Dark Reading".
Dark Reading
Holiday Scams Drive SMS Phishing Attacks
Attackers typically target consumers with malicious text messages containing obfuscated links, but experts say businesses are threatened as well.
βΌ CVE-2021-36333 βΌ
π Read
via "National Vulnerability Database".
Dell EMC CloudLink 7.1 and all prior versions contain a Buffer Overflow Vulnerability. A local low privileged attacker, may potentially exploit this vulnerability, leading to an application crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24812 βΌ
π Read
via "National Vulnerability Database".
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.π Read
via "National Vulnerability Database".
βΌ CVE-2021-21561 βΌ
π Read
via "National Vulnerability Database".
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36313 βΌ
π Read
via "National Vulnerability Database".
Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it may be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24892 βΌ
π Read
via "National Vulnerability Database".
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To exploit this vulnerability, an attacker must register to obtain a valid WordPress's user and use such user to authenticate with WordPress in order to exploit the vulnerable edit function.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36314 βΌ
π Read
via "National Vulnerability Database".
Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary files on the end user system.π Read
via "National Vulnerability Database".