πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28819 β€Ό

Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26366 β€Ό

An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26362 β€Ό

A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26361 β€Ό

A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22531 β€Ό

A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29368 β€Ό

Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26351 β€Ό

Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26368 β€Ό

Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28818 β€Ό

ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29369 β€Ό

Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Egnyte Enhances Program for Managed Service Providers πŸ•΄

Enhancements to the program include unique packages, faster response time for invoicing, and dedicated training for new solutions.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cloud Firm Appian Awarded $2B in Trade Secret Cyber-Theft Lawsuit πŸ•΄

Cloud competitor found liable for breaking into Appian back-end systems to steal company secrets.

πŸ“– Read

via "Dark Reading".
πŸ•΄ StackHawk Raises $20.7 Million in Series B Funding for Developer-First Application and API Security Testing πŸ•΄

Round co-led by Sapphire Ventures and Costanoa Ventures to accelerate product leadership and market growth.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 3 Predictors of Cybersecurity Startup Success πŸ•΄

Before investing, venture capitalists should consider a trio of business characteristics that seem to correlate with commercial success, based on meetings with over 2,000 cybersecurity startups.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-27500 β€Ό

A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22798 β€Ό

Sysaid Γ’β‚¬β€œ Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP, then he needs to change the path in the URL to /ConcurrentLogin%2ejsp after that he will receive an error message with a login button, by clicking on it, he will connect to the system dashboard. The attacker can receive sensitive data like server details, usernames, workstations, etc. He can also perform actions such as uploading files, deleting calls from the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22971 β€Ό

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22984 β€Ό

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22987 β€Ό

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23165 β€Ό

Sysaid Γ’β‚¬β€œ Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treecontent.jsp" suffers from a Reflected Cross-Site Scripting vulnerability. For an attacker to exploit this Cross-Site Scripting vulnerability, it's necessary for the affected product to expose the Offline Help Pages. An attacker may gain access to sensitive information or execute client-side code in the browser session of the victim user. Furthermore, an attacker would require the victim to open a malicious link. An attacker may exploit this vulnerability in order to perform phishing attacks. The attacker can receive sensitive data like server details, usernames, workstations, etc. He can also perform actions such as uploading files, deleting calls from the system

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23139 β€Ό

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. ItÒ€ℒs easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.

πŸ“– Read

via "National Vulnerability Database".