πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-44167 β€Ό

An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories via symbolic links.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-27656 β€Ό

The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1622 β€Ό

LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28214 β€Ό

During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systemsÒ€ℒ Confidentiality, Integrity, and Availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29977 β€Ό

There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28774 β€Ό

Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29898 β€Ό

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29009 β€Ό

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29610 β€Ό

SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28077 β€Ό

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29008 β€Ό

An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1623 β€Ό

LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29932 β€Ό

The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29611 β€Ό

SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29006 β€Ό

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28078 β€Ό

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29897 β€Ό

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29978 β€Ό

There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29007 β€Ό

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29613 β€Ό

Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Quantum Ransomware Strikes Quickly, How to Prepare and Recover πŸ•΄

NYC-area cybersecurity expert shares the anatomy of a Quantum Ransomware attack and how to prevent, detect and recover from a ransomware attack, in a new article from eMazzanti Technologies.

πŸ“– Read

via "Dark Reading".