πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1232 β€Ό

Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28446 β€Ό

The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1311 β€Ό

Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1314 β€Ό

Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28462 β€Ό

This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26307 β€Ό

LibreOffice supports the storage of passwords for web connections in the userÒ€ℒs configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34963 β€Ό

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28459 β€Ό

This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Logwatch 7.7 πŸ› 

Logwatch analyzes and reports on unix system logs. It is a customizable and pluggable log monitoring system which will go through the logs for a given period of time and make a customizable report. It should work right out of the package on most systems.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2020-28438 β€Ό

This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28445 β€Ό

This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26306 β€Ό

LibreOffice supports the storage of passwords for web connections in the userÒ€ℒs configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34964 β€Ό

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34961 β€Ό

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-28422 β€Ό

All versions of package git-archive are vulnerable to Command Injection via the exports function.

πŸ“– Read

via "National Vulnerability Database".
⚠ T-Mobile to cough up $500 million over 2021 data breach ⚠

Technically, it's not a fine, and the lawyers will get a big chunk of it. But it still adds up to a half-billion-dollar data breach.

πŸ“– Read

via "Naked Security".
πŸ•΄ Qakbot Is Back With a New Trick: DLL Sideloading πŸ•΄

In the latest iteration, Qakbot operators are using DLL sideloading to deliver malware, a technique that places legitimate and malicious files together in a common directory to avoid detection.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-35650 β€Ό

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35649 β€Ό

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

πŸ“– Read

via "National Vulnerability Database".
πŸ€”1
β€Ό CVE-2022-35653 β€Ό

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24083 β€Ό

Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

πŸ“– Read

via "National Vulnerability Database".