πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks πŸ—“οΈ

Unpatched flaw caused by the predictability of transaction IDs

πŸ“– Read

via "The Daily Swig".
⚠ Firefox hits 100*, fixes bugs… but no new zero-days this month ⚠

Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.

πŸ“– Read

via "Naked Security".
πŸ•΄ AI for Cybersecurity Shimmers With Promise, But Challenges Abound πŸ•΄

Companies see AI-powered cybersecurity tools and systems as the future, but at present nearly 90% of them say they face significant hurdles in making use of them.

πŸ“– Read

via "Dark Reading".
⚠ Android monthly updates are out – critical bugs found in critical places! ⚠

Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29347 β€Ό

An arbitrary file upload vulnerability in Web@archiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28552 β€Ό

Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28081 β€Ό

A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to execute arbitrary web scripts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27903 β€Ό

An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25784 β€Ό

Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28512 β€Ό

A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28076 β€Ό

Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28487 β€Ό

Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25787 β€Ό

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28066 β€Ό

Libarchive v3.6.0 was discovered to contain a read memory access vulnerability via the function lzma_decode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25785 β€Ό

Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25781 β€Ό

Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28067 β€Ό

An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in the Sandbox via a crafted executable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28488 β€Ό

The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25783 β€Ό

Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28806 β€Ό

An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410), v2.13 (U7310), and v1.09 (E459/E449). The FjGabiFlashCoreAbstractionSmm driver registers a Software System Management Interrupt (SWSMI) handler that is not sufficiently validated to ensure that the CommBuffer (or any other communication buffer's nested contents) are not pointing to SMRAM contents. A potential attacker can therefore write fixed data to SMRAM, which could lead to data corruption inside this memory (e.g., change the SMI handler's code or modify SMRAM map structures to break input pointer validation for other SMI handlers). Thus, the attacker could elevate privileges from ring 0 to ring -2 and execute arbitrary code in SMM.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25780 β€Ό

Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope.

πŸ“– Read

via "National Vulnerability Database".