βΌ CVE-2022-40297 βΌ
π Read
via "National Vulnerability Database".
UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password.π Read
via "National Vulnerability Database".
βοΈ Transacting in Person with Strangers from the Internet βοΈ
π Read
via "Krebs on Security".
Communities like Craigslist, OfferUp, Facebook Marketplace and others are great for finding low- or no-cost stuff that one can pick up directly from a nearby seller, and for getting rid of useful things that don't deserve to end up in a landfill. But when dealing with strangers from the Internet, there is always a risk that the person you've agreed to meet has other intentions.π Read
via "Krebs on Security".
Krebs on Security
Transacting in Person with Strangers from the Internet
Communities like Craigslist, OfferUp, Facebook Marketplace and others are great for finding low- or no-cost stuff that one can pick up directly from a nearby seller, and for getting rid of useful things that don't deserve to end up inβ¦
ποΈ ManageEngine vulnerability posed code injection risk for password management software ποΈ
π Read
via "The Daily Swig".
Authentication-free flaw opened the door to a raft of exploitsπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
ManageEngine vulnerability posed code injection risk for password management software
Authentication-free flaw opened the door to a raft of exploits
ποΈ Six-year-old blind SSRF vulnerability in WordPress Core feature could enable DDoS attacks ποΈ
π Read
via "The Daily Swig".
Issue present in pingback requests featureπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Six-year-old blind SSRF vulnerability in WordPress Core feature could enable DDoS attacks
Issue present in pingback requests feature
π Friday Five 9/9 π
π Read
via "".
This week saw two social media giants come under fire once again, malware that cons cybercriminals, and more cyberattacks in Ukraine. Read about these stories and more in this week's Friday Five!
π Read
via "".
βΌ CVE-2022-38144 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36861 βΌ
π Read
via "National Vulnerability Database".
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26390 βΌ
π Read
via "National Vulnerability Database".
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36793 βΌ
π Read
via "National Vulnerability Database".
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36869 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36423 βΌ
π Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36864 βΌ
π Read
via "National Vulnerability Database".
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36852 βΌ
π Read
via "National Vulnerability Database".
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38286 βΌ
π Read
via "National Vulnerability Database".
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36863 βΌ
π Read
via "National Vulnerability Database".
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36847 βΌ
π Read
via "National Vulnerability Database".
Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38457 βΌ
π Read
via "National Vulnerability Database".
A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).π Read
via "National Vulnerability Database".
βΌ CVE-2022-40191 βΌ
π Read
via "National Vulnerability Database".
Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin <= 1.2.4 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38058 βΌ
π Read
via "National Vulnerability Database".
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36842 βΌ
π Read
via "National Vulnerability Database".
A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36855 βΌ
π Read
via "National Vulnerability Database".
A use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.π Read
via "National Vulnerability Database".