βΌ CVE-2021-41027 βΌ
π Read
via "National Vulnerability Database".
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36190 βΌ
π Read
via "National Vulnerability Database".
A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.π Read
via "National Vulnerability Database".
βΌ CVE-2021-26108 βΌ
π Read
via "National Vulnerability Database".
A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.π Read
via "National Vulnerability Database".
π¦Ώ Telemedicine: Doctors and patients are both worried about privacy and data security π¦Ώ
π Read
via "Tech Republic".
Kaspersky survey finds 34% of telehealth providers admit to a wrong diagnosis due to poor video or photo quality.π Read
via "Tech Republic".
TechRepublic
Telemedicine: Doctors and patients are both worried about privacy and data security
Kaspersky survey finds 34% of telehealth providers admit to a wrong diagnosis due to poor video or photo quality.
β Firefox update brings a whole new sort of security sandbox β
π Read
via "Naked Security".
Firefox 95.0 is out, with the usual security fixes... plus some funky new ones.π Read
via "Naked Security".
Naked Security
Firefox update brings a whole new sort of security sandbox
Firefox 95.0 is out, with the usual security fixes⦠plus some funky new ones.
π¦Ώ Cybersecurity: Organizations face key obstacles in adopting zero trust π¦Ώ
π Read
via "Tech Republic".
Security pros surveyed by One Identity cited a lack of clarity, other priorities and a lack of resources as bumps on the road to Zero Trust.π Read
via "Tech Republic".
TechRepublic
Cybersecurity: Organizations face key obstacles in adopting zero trust
Security pros surveyed by One Identity cited a lack of clarity, other priorities and a lack of resources as bumps on the road to zero trust.
π ETS5 Password Recovery Tool π
π Read
via "Packet Storm Security".
ETS Password Recovery Tool allows you to recover passwords for an ETS5 project. This is due to a significant design flaw as ETS5 uses a hard-coded password and salt to encrypt the project information.π Read
via "Packet Storm Security".
Packetstormsecurity
ETS5 Password Recovery Tool β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
ποΈ US Department of Homeland Security heeds calls for tougher transport cybersecurity rules ποΈ
π Read
via "The Daily Swig".
TSA issues mandatory requirements for βhigh-riskβ rail infrastructureπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
US Department of Homeland Security heeds calls for tougher transport cybersecurity rules
TSA issues mandatory requirements for βhigh-riskβ rail infrastructure
βΌ CVE-2021-41450 βΌ
π Read
via "National Vulnerability Database".
An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25521 βΌ
π Read
via "National Vulnerability Database".
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25524 βΌ
π Read
via "National Vulnerability Database".
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37097 βΌ
π Read
via "National Vulnerability Database".
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25513 βΌ
π Read
via "National Vulnerability Database".
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37069 βΌ
π Read
via "National Vulnerability Database".
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25512 βΌ
π Read
via "National Vulnerability Database".
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37050 βΌ
π Read
via "National Vulnerability Database".
There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37054 βΌ
π Read
via "National Vulnerability Database".
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25518 βΌ
π Read
via "National Vulnerability Database".
An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25511 βΌ
π Read
via "National Vulnerability Database".
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2021-25510 βΌ
π Read
via "National Vulnerability Database".
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37037 βΌ
π Read
via "National Vulnerability Database".
There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart.π Read
via "National Vulnerability Database".