โผ CVE-2022-31201 โผ
๐ Read
via "National Vulnerability Database".
SoftGuard Web (SGW) before 5.1.5 allows HTML injection.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-31209 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcpy() without checking the string length beforehand.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-28807 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-26482 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-28808 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-31211 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-40150 โผ
๐ Read
via "National Vulnerability Database".
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-31210 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be deactivated or have their passwords changed, they are considered to be backdoor accounts.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-28809 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-30982 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-31213 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file.๐ Read
via "National Vulnerability Database".
๐คฏ1
โผ CVE-2022-29286 โผ
๐ Read
via "National Vulnerability Database".
Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-31212 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-26479 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.๐ Read
via "National Vulnerability Database".
โผ CVE-2016-15003 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-33891 โผ
๐ Read
via "National Vulnerability Database".
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.๐ Read
via "National Vulnerability Database".
โ 7 cybersecurity tips for your summer vacation! โ
๐ Read
via "Naked Security".
Here you go - seven thoughtful cybersecurity tips to help you travel safely...๐ Read
via "Naked Security".
Naked Security
7 cybersecurity tips for your summer vacation!
Here you go โ seven thoughtful cybersecurity tips to help you travel safelyโฆ
โ CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2 โ
๐ Read
via "Threat Post".
Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.๐ Read
via "Threat Post".
Threat Post
CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2
Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.
โ Google Boots Multiple Malware-laced Android Apps from Marketplace โ
๐ Read
via "Threat Post".
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.๐ Read
via "Threat Post".
Threat Post
Google Boots Multiple Malware-laced Android Apps from Marketplace
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.
๐๏ธ Prototype pollution in Blitz.js leads to remote code execution ๐๏ธ
๐ Read
via "The Daily Swig".
Chain of exploits could be triggered without any authentication๐ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Prototype pollution in Blitz.js leads to remote code execution
Chain of exploits could be triggered without any authentication
๐ด Watch Out for User Impersonation in Low-Code/No-Code Apps ๐ด
๐ Read
via "Dark Reading".
How a well-meaning employee could unwittingly share their identity with other users, causing a whole range of problems across IT, security, and the business.๐ Read
via "Dark Reading".
Dark Reading
Watch Out for User Impersonation in Low-Code/No-Code Apps
How a well-meaning employee could unwittingly share their identity with other users, causing a whole range of problems across IT, security, and the business.