πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-26514 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0343 β€Ό

A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyond 24.2

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0923 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44081 β€Ό

A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26887 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27175 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25347 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26338 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_hierarchyHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26666 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialogECC.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26839 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22934 β€Ό

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minionÒ€ℒs public key, which can result in attackers substituting arbitrary pillar data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26667 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26013 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26065 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetLatestDemandNode and GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1050 β€Ό

Guest driver might execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26836 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22941 β€Ό

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26069 β€Ό

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ CriticalStart Releases Enhanced Capabilities for Microsoft 365 Defender πŸ•΄

Latest enhancements allow customers to leverage Microsoft 365 Defender and MDR to respond to breaches stemming from user account-based attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1122 β€Ό

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-22948 β€Ό

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

πŸ“– Read

via "National Vulnerability Database".