πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-34641 β€Ό

CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occurs during address translation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34639 β€Ό

CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34634 β€Ό

CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34632 β€Ό

Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34640 β€Ό

The *tval of ecall/ebreak in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a was discovered to be incorrect.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34636 β€Ό

CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occurs during address translation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34637 β€Ό

CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34633 β€Ό

CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34643 β€Ό

RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b5 implements the incorrect exception priotrity when accessing memory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34635 β€Ό

The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30526 β€Ό

A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.09 through 4.72, which could allow a local attacker to execute some OS commands with root privileges in some directories on a vulnerable device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30532 β€Ό

In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2030 β€Ό

A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.11 through 4.72, that could allow an authenticated attacker to access some restricted files on a vulnerable device.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ LDAP Account Manager bug poses unauthenticated remote code execution risk πŸ—“οΈ

Silence of the LAM

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-2467 β€Ό

A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2468 β€Ό

A vulnerability was found in SourceCodester Garage Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /editbrand.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Tor Browser 11.5 release enables users to automatically circumvent censorship πŸ—“οΈ

New update addresses challenges faced by users in repressive countries

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Protecting Against Kubernetes-Borne Ransomware πŸ•΄

The conventional wisdom that virtual container environments were somehow immune from malware and hackers has been upended.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Enso Security Leads Industry Mission to Bring Control to Chaos With Community-Driven AppSec Map πŸ•΄

Builds personalization, posture scoring and enhanced market intelligence into interactive map of the application security ecosystem.

πŸ“– Read

via "Dark Reading".
πŸ•΄ GhangorCloud Announces CAPE, a Next Generation Unified Compliance and Data Privacy Enforcement Solution πŸ•΄

New CAPE platform delivers patented intelligent automation and enforcement of consumer data privacy mandates at lowest total cost of ownership.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ β€˜Password extraction risk’ in identity provider Okta disputed πŸ—“οΈ

Researchers go public after vendor disputes impersonation threat

πŸ“– Read

via "The Daily Swig".
πŸ‘1