πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-38694 β€Ό

SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38785 β€Ό

There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38784 β€Ό

There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Chrome to bolster CSRF protections with CORS preflight checks on private network requests πŸ—“οΈ

Phased rollout begins from Chrome 98 with DevTools warnings of failed preflight requests

πŸ“– Read

via "The Daily Swig".
❌ Critical ManageEngine Desktop Server Bug Opens Orgs to Malware ❌

Zoho's comprehensive endpoint-management platform suffers from an authentication-bypass bug (CVE-2021-44757) that could lead to remote code execution.

πŸ“– Read

via "Threat Post".
πŸ•΄ Name That Toon: Nowhere to Hide πŸ•΄

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-38695 β€Ό

SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in certain fields (e.g. subject, description) of the document form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38697 β€Ό

SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0262 β€Ό

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23302 β€Ό

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0260 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0261 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23307 β€Ό

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38696 β€Ό

SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4146 β€Ό

Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41550 β€Ό

Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23305 β€Ό

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44217 β€Ό

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41551 β€Ό

Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0263 β€Ό

Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜White Rabbit’ Ransomware May Be New FIN8 Tool ❌

It's a double-extortion play that uses the command-line password β€˜KissMe’ to hide its nasty acts and adorns its ransom note with cutesy ASCII bunny art.

πŸ“– Read

via "Threat Post".