πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1048 β€Ό

A use-after-free flaw was found in the Linux kernelÒ€ℒs sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3982 β€Ό

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1015 β€Ό

A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29934 β€Ό

USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0985 β€Ό

Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1402 β€Ό

ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4206 β€Ό

A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1403 β€Ό

ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds write condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43938 β€Ό

Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36207 β€Ό

Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cloudflare Flags Largest HTTPS DDoS Attack It's Ever Recorded πŸ•΄

This scale of this month's encrypted DDoS attack over HTTPS suggests a well-resourced operation, analysts say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1543 β€Ό

Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Critical Vulnerabilities Leave Some Network-Attached Storage Devices Open to Attack πŸ•΄

QNAP and Synology say flaws in the Netatalk fileserver allow remote code execution and information disclosure.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25854 β€Ό

This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29947 β€Ό

Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28198 β€Ό

NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29945 β€Ό

DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Good News! IAM Is Near-Universal With SaaS πŸ•΄

The less-good news: IAM only works for applications your IT department knows about, so watch for "shadow IT" programs installed or written by users that leave a security gap.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-29967 β€Ό

static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 2022 Security Priorities: Staffing and Remote Work πŸ•΄

A comprehensive security strategy balances technology, processes, and people β€” and hiring and retaining security personnel and securing the remote workforce are firmly people priorities.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-29265 β€Ό

Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors attempt to resolve XML External Entity references when configured with default property values: - EvaluateXPath - EvaluateXQuery - ValidateXml Apache NiFi flow configurations that include these Processors are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations in the default configuration for these Processors, and disallows XML External Entity resolution in standard services.

πŸ“– Read

via "National Vulnerability Database".