πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-26869 β€Ό

Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26868 β€Ό

Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover by an attacker.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29718 β€Ό

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22557 β€Ό

PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32250 β€Ό

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26866 β€Ό

Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29085 β€Ό

Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42877 β€Ό

TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29084 β€Ό

Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29767 β€Ό

adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a Denial of Service (DoS) via high CPU usage due to a large number of connections.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ IT Pro News In Review: Businesses cancel cyber policies, EE milestone, Costa Rica Conti attack πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ“’ The cookie phase-out might precede an AdTech apocalypse πŸ“’

With the industry phasing out third-party cookies, what does this mean for businesses reliant on them to track and improve their campaigns?

πŸ“– Read

via "ITPro".
πŸ“’ DOE β€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œβ€Œfundsβ€Œ β€Œdevelopment of Qunnect's Quantum Repeater πŸ“’

The $1.85 million grant will eventually pave the way for quantum internet

πŸ“– Read

via "ITPro".
πŸ“’ Ministry of Defence pledges resilience to all known vulnerabilities and cyber attack methods by 2030 πŸ“’

New MoD cyber security strategy is underpinned by a 'secure by design' approach that will run across the organisation

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-32271 β€Ό

In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1987 β€Ό

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32265 β€Ό

qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1988 β€Ό

Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32270 β€Ό

In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32268 β€Ό

StarWind SAN and NAS v0.2 build 1914 allow remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32269 β€Ό

In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".