πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-30228 β€Ό

A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6), SICAM GridEdge Essential Intel (All versions < V2.6.6), SICAM GridEdge Essential with GDS ARM (All versions < V2.6.6), SICAM GridEdge Essential with GDS Intel (All versions < V2.6.6). The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. In case an attacker tricks a legitimate user into accessing a special resource a malicious request could be executed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35111 β€Ό

Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35104 β€Ό

Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40649 β€Ό

In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22064 β€Ό

Possible buffer over read due to lack of size validation while unpacking frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35096 β€Ό

Improper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22086 β€Ό

Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27219 β€Ό

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22068 β€Ό

kernel event may contain unexpected content which is not generated by NPU software in asynchronous execution mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ GhostTouch: Hackers can reach your phone’s touchscreen without even touching it πŸ—“οΈ

New research shows how electromagnetic interference can be used to trigger arbitrary behavior on mobile touchscreens, although caveats apply

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Understanding and Mitigating Single Sign-on Risk πŸ•΄

SSO's one-to-many architecture is both a big advantage and a weakness.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40678 β€Ό

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31273 β€Ό

An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Oblivious DNS-over-HTTPS offers privacy enhancements to secure lookup protocol πŸ—“οΈ

ODoH is said to enhance user privacy without compromising performance

πŸ“– Read

via "The Daily Swig".
πŸ‘1πŸ‘Ž1
πŸ—“οΈ LenelS2 access control vulnerabilities leave door open to lock manipulation πŸ—“οΈ

Vendor addresses threat to integrity and availability of physical access systems

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Optiv MXDR Enhances Detection Coverage With Expanded Cloud Integration πŸ•΄

Service ingests AWS, GCP and Microsoft Azure data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-40660 β€Ό

An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32336 β€Ό

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27889 β€Ό

The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail for the duration of the attack. This could lead to performance degradation or login failures for customer Palantir Foundry environments. This vulnerability is resolved in Multipass 3.647.0. This issue affects: Palantir Foundry Multipass versions prior to 3.647.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31845 β€Ό

A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31309 β€Ό

A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive router information via execution of the exec cmd function.

πŸ“– Read

via "National Vulnerability Database".