πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28462 β€Ό

novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29939 β€Ό

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29938 β€Ό

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29339 β€Ό

In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42242 β€Ό

A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28471 β€Ό

In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29940 β€Ό

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29340 β€Ό

GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1575 β€Ό

Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28461 β€Ό

mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Docker Under Siege: Cybercriminals Compromise Honeypots to Ramp Up Attacks πŸ•΄

Cloud containers are increasingly part of the cybercrime playbook, with researchers flagging ongoing scanning for Docker weaknesses along with rapid exploitation to infect systems with coin-miners, denial-of-service tools, and ransomware.

πŸ“– Read

via "Dark Reading".
⚠ World Password Day – the 1960s just called and gave you your passwords back ⚠

Yes, passwords are going away. No, it won't happen tomorrow. So it's still worth knowing the basics of picking proper passwords.

πŸ“– Read

via "Naked Security".
πŸ•΄ 1,000+ Attacks in 2 Years: How the SideWinder APT Sheds Its Skin πŸ•΄

Researcher to reveal fresh details at Black Hat Asia on a tenacious cyber-espionage group attacking specific military, law enforcement, aviation, and other entities in Central and South Asia.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-1464 β€Ό

Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42183 β€Ό

MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1516 β€Ό

A NULL pointer dereference flaw was found in the Linux kernelÒ€ℒs X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of this connection. This flaw allows a local user to crash the system.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Multichannel Phishing Concerns Cybersecurity Leaders in 2022 πŸ•΄

With 80% of companies using cloud collaboration tools, cybercriminals are using multichannel phishing attacks to exploit security gaps in the hybrid work model.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cisco Announces Cloud Controls Framework Is Now Available to Public πŸ•΄

The Cisco CCF helps save resources by enabling organizations to achieve cloud security certifications more efficiently.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Critical Cisco VM-Escape Bug Threatens Host Takeover πŸ•΄

The vendor also disclosed two other security vulnerabilities that would allow remote, unauthenticated attackers to inject commands as root and snoop on sensitive user information.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Magnet Forensics Acquires Cybersecurity Software Firm Comae Technologies πŸ•΄

The company will continue the development of Comae’s memory analysis platform and seek to incorporate its capabilities into existing solutions

πŸ“– Read

via "Dark Reading".
πŸ›  Wireshark Analyzer 3.6.5 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".