π΄ Name That Toon: Knives Out π΄
π Read
via "Dark Reading".
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.π Read
via "Dark Reading".
Dark Reading
Name That Toon: Knives Out
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
π΄ NSA Cyber Chief Vows 'No Backdoors' in Quantum Encryption Standards π΄
π Read
via "Dark Reading".
New quantum encryption standards will stand up to spy-snooping, NSA cybersecurity director said.π Read
via "Dark Reading".
Dark Reading
NSA Cyber Chief Vows 'No Backdoors' in Quantum Encryption Standards
New quantum encryption standards will stand up to spy-snooping, NSA cybersecurity director said.
βΌ CVE-2022-25169 βΌ
π Read
via "National Vulnerability Database".
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.π Read
via "National Vulnerability Database".
βΌ CVE-2021-23266 βΌ
π Read
via "National Vulnerability Database".
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33318 βΌ
π Read
via "National Vulnerability Database".
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP addresses and subnets.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30050 βΌ
π Read
via "National Vulnerability Database".
Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-23267 βΌ
π Read
via "National Vulnerability Database".
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.π Read
via "National Vulnerability Database".
π΄ You Can't Opt Out of Citizen Development π΄
π Read
via "Dark Reading".
To see why low-code/no-code is inevitable, we need to first understand how it finds its way into the enterprise.π Read
via "Dark Reading".
Dark Reading
You Can't Opt Out of Citizen Development
To see why low-code/no-code is inevitable, we need to first understand how it finds its way into the enterprise.
βΌ CVE-2022-30055 βΌ
π Read
via "National Vulnerability Database".
Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution.π Read
via "National Vulnerability Database".
βΌ CVE-2021-23265 βΌ
π Read
via "National Vulnerability Database".
A logged-in and authenticated user with a Reviewer Role may lock a content item.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30126 βΌ
π Read
via "National Vulnerability Database".
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0π Read
via "National Vulnerability Database".
π΄ Open Source Security Gets $150M Boost From Industry Heavy Hitters π΄
π Read
via "Dark Reading".
Maintainers of open source software (OSS) will gain additional security tools for their own projects, while the developers who use OSS β and about 97% of software does β will gain more data on security.π Read
via "Dark Reading".
Dark Reading
Open Source Security Gets $30M Boost From Industry Heavy Hitters
Maintainers of open source software (OSS) will gain additional security tools for their own projects, while the developers who use OSS β and about 97% of software does β will gain more data on security.
βΌ CVE-2022-30696 βΌ
π Read
via "National Vulnerability Database".
Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640π Read
via "National Vulnerability Database".
βΌ CVE-2022-1679 βΌ
π Read
via "National Vulnerability Database".
A use-after-free flaw was found in the Linux kernelΓ’β¬β’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1731 βΌ
π Read
via "National Vulnerability Database".
Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.π Read
via "National Vulnerability Database".
βΌ CVE-2021-27442 βΌ
π Read
via "National Vulnerability Database".
The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.π Read
via "National Vulnerability Database".
βΌ CVE-2021-27446 βΌ
π Read
via "National Vulnerability Database".
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33021 βΌ
π Read
via "National Vulnerability Database".
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter Γ’β¬ΛedateΓ’β¬β’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30697 βΌ
π Read
via "National Vulnerability Database".
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640π Read
via "National Vulnerability Database".
βΌ CVE-2022-30695 βΌ
π Read
via "National Vulnerability Database".
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640π Read
via "National Vulnerability Database".
βΌ CVE-2021-33025 βΌ
π Read
via "National Vulnerability Database".
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.π Read
via "National Vulnerability Database".