πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-37153 β€Ό

An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27812 β€Ό

Flooding SNS firewall 3.7.0 to 3.7.26 with udp or icmp randomizing the source through an internal to internal or external to internal interfaces will lead the firewall to overwork. It will consume 100% CPU, 100 RAM and won't be available and can crash.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
❌ Twitter Whistleblower Complaint: The TL;DR Version ❌

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-0887 β€Ό

In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-236848817

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0891 β€Ό

An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Product: AndroidVersions: Android SoCAndroid ID: A-236849490

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0946 β€Ό

The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it does the buffer will be left uninitialized and despite the error will still be copied to userspace. Kernel leak of uninitialized heap data with no privs required.Product: AndroidVersions: Android SoCAndroid ID: A-236846966

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0698 β€Ό

In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-236848165

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20122 β€Ό

The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232441339

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39815 β€Ό

The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232440670

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0947 β€Ό

The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for several reasons including invalid sizes. If this method fails the buffer will be left uninitialized and despite the error will still be copied to userspace. Kernel leak of uninitialized heap data with no privs required.Product: AndroidVersions: Android SoCAndroid ID: A-236838960

πŸ“– Read

via "National Vulnerability Database".
⚠ Bitcoin ATMs leeched by attackers who created fake admin accounts ⚠

The criminals didn't implant any malware. The attack was orchestrated via malevolent configuration changes.

πŸ“– Read

via "Naked Security".
⚠ Breaching airgap security: using your phone’s compass as a microphone! ⚠

One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...

πŸ“– Read

via "Naked Security".
πŸ•΄ VMware LPE Bug Allows Cyberattackers to Feast on Virtual Machine Data πŸ•΄

An insider threat or remote attacker with initial access could exploit CVE-2022-31676 to steal sensitive data and scoop up user credentials for follow-on attacks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-4209 β€Ό

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4204 β€Ό

An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4158 β€Ό

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3488 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4122 β€Ό

It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3998 β€Ό

A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4125 β€Ό

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4189 β€Ό

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.

πŸ“– Read

via "National Vulnerability Database".