πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-22551 β€Ό

DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46244 β€Ό

A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46237 β€Ό

An untrusted pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36338 β€Ό

Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36339 β€Ό

The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39480 β€Ό

Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46240 β€Ό

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46242 β€Ό

HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23837 β€Ό

In api.rb in Sidekiq before 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23366 β€Ό

HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21708 β€Ό

graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug in the library that would allow an attacker with specifically designed queries to cause stack overflow panics. Any user with access to the GraphQL handler can send these queries and cause stack overflows. This in turn could potentially compromise the ability of the server to serve data to its users. The issue has been patched in version `v1.3.0`. The only known workaround for this issue is to disable the `graphql.MaxDepth` option from your schema which is not recommended.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23808 β€Ό

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23807 β€Ό

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4172 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4103 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23850 β€Ό

xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a crafted EPUB document.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46024 β€Ό

Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45380 β€Ό

AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23852 β€Ό

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23858 β€Ό

In StarWind Command Center before V2 build 6021, an authenticated read-only user can elevate privileges to administrator through the REST API.

πŸ“– Read

via "National Vulnerability Database".
❌ Unusual β€˜Donald Trump’ Packer Malware Delivers RATs, Infostealers ❌

The β€˜DTPacker’ downloader used fake Liverpool Football Club sites as lures for several weeks, a report finds.

πŸ“– Read

via "Threat Post".