πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28906 β€Ό

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26988 β€Ό

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28915 β€Ό

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29323 β€Ό

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29328 β€Ό

D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29321 β€Ό

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29324 β€Ό

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.

πŸ“– Read

via "National Vulnerability Database".
⚠ Colonial Pipeline facing $1,000,000 fine for poor recovery plans ⚠

How good is your cybersecurity? Are you making the same mistakes as lots of other people? Here's some real-life advice...

πŸ“– Read

via "Naked Security".
πŸ•΄ Lincoln College Set to Close After Crippling Cyberattack πŸ•΄

COVID-19 and a December 2021 cyberattack combined to put the future of Abraham Lincoln's namesake college in peril.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-39024 β€Ό

IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213862.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22774 β€Ό

The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.0 and 8.4.1, TIBCO Managed File Transfer Internet Server: versions 8.3.1 and below, and TIBCO Managed File Transfer Internet Server: versions 8.4.0 and 8.4.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1649 β€Ό

Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22454 β€Ό

IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ US Pledges to Help Ukraine Keep the Internet and Lights On πŸ•΄

US State Department outlines coordinated government effort to provide Ukraine with cybersecurity intelligence, expertise, and resources amid invasion.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24466 β€Ό

Windows Hyper-V Security Feature Bypass Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20006 β€Ό

In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's under the lockscreen due to a race condition. This could lead to local escalation of privilege if a Guest user is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-151095871

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1453 β€Ό

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29129 β€Ό

Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29130, CVE-2022-29131, CVE-2022-29137, CVE-2022-29139, CVE-2022-29141.

πŸ“– Read

via "National Vulnerability Database".
🀯1
β€Ό CVE-2022-20115 β€Ό

In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-210118427

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20008 β€Ό

In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216481035References: Upstream kernel

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26930 β€Ό

Windows Remote Access Connection Manager Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".