β Cryptocurrency startup fails to subtract before adding, loses $31m β
π Read
via "Naked Security".
Think of a number, any number. Take away 42. Add 42 back in. Then pretend you didn't take away 42. How much is left?π Read
via "Naked Security".
Naked Security
Cryptocurrency startup fails to subtract before adding, loses $31m
Think of a number, any number. Take away 42. Add 42 back in. Then pretend you didnβt take away 42. How much is left?
π¦Ώ How employee burnout may be putting your organization at risk π¦Ώ
π Read
via "Tech Republic".
With pandemic-induced pressures impacting many employees, burnout can easily lead to security risks, says 1Password.π Read
via "Tech Republic".
TechRepublic
How employee burnout may be putting your organization at risk
With pandemic-induced pressures impacting many employees, burnout can easily lead to security risks, says 1Password.
βΌ CVE-2021-37062 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory overflow and information leakage.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37094 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37077 βΌ
π Read
via "National Vulnerability Database".
There is a NULL Pointer Dereference vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37068 βΌ
π Read
via "National Vulnerability Database".
There is a Resource Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of Service Attacks.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37086 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sandbox.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37079 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37064 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to arbitrary file created.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37020 βΌ
π Read
via "National Vulnerability Database".
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37081 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to nearby crash.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37095 βΌ
π Read
via "National Vulnerability Database".
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37099 βΌ
π Read
via "National Vulnerability Database".
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37061 βΌ
π Read
via "National Vulnerability Database".
There is a Uncontrolled Resource Consumption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Screen projection application denial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37096 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43176 βΌ
π Read
via "National Vulnerability Database".
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 takes a user-supplied Γ’β¬ΕactionΓ’β¬οΏ½ parameter and appends a .php file extension to locate and load the correct PHP file to implement the API call. Vulnerable versions of GOautodial do not sanitize the user input that specifies the action. This permits an attacker to execute any PHP source file with a .php extension that is present on the disk and readable by the GOautodial web server process. Combined with CVE-2021-43175, it is possible for the attacker to do this without valid credentials. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:Cπ Read
via "National Vulnerability Database".
βΌ CVE-2021-43789 βΌ
π Read
via "National Vulnerability Database".
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed in version 1.7.8.2.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43175 βΌ
π Read
via "National Vulnerability Database".
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOautodial validate the username and password incorrectly, allowing the caller to specify any values for these parameters and successfully authenticate. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:Cπ Read
via "National Vulnerability Database".
βΌ CVE-2021-37091 βΌ
π Read
via "National Vulnerability Database".
There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37014 βΌ
π Read
via "National Vulnerability Database".
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to device cannot be used properly.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37100 βΌ
π Read
via "National Vulnerability Database".
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.π Read
via "National Vulnerability Database".