βΌ CVE-2022-38064 βΌ
π Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38701 βΌ
π Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36376 βΌ
π Read
via "National Vulnerability Database".
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40133 βΌ
π Read
via "National Vulnerability Database".
A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).π Read
via "National Vulnerability Database".
βΌ CVE-2022-36876 βΌ
π Read
via "National Vulnerability Database".
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36858 βΌ
π Read
via "National Vulnerability Database".
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38059 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin <= 1.0.3 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-37404 βΌ
π Read
via "National Vulnerability Database".
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Salazar's add2fav plugin <= 1.0 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38285 βΌ
π Read
via "National Vulnerability Database".
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36422 βΌ
π Read
via "National Vulnerability Database".
Rating increase/decrease via race condition in Lester 'GaMerZ' Chan WP-PostRatings plugin <= 1.89 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38096 βΌ
π Read
via "National Vulnerability Database".
A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).π Read
via "National Vulnerability Database".
βΌ CVE-2022-38279 βΌ
π Read
via "National Vulnerability Database".
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36873 βΌ
π Read
via "National Vulnerability Database".
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3147 βΌ
π Read
via "National Vulnerability Database".
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35725 βΌ
π Read
via "National Vulnerability Database".
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at WordPress.π Read
via "National Vulnerability Database".
β€1
β S3 Ep99: TikTok βattackβ β was there a data breach, or not? [Audio + Text] β
π Read
via "Naked Security".
Latest episode - listen now! (Or read if you prefer - full transcript inside.)π Read
via "Naked Security".
Naked Security
S3 Ep99: TikTok βattackβ β was there a data breach, or not? [Audio + Text]
Latest episode β listen now! (Or read if you prefer β full transcript inside.)
β How to deal with dates and times without any timezone tantrumsβ¦ β
π Read
via "Naked Security".
Heartfelt encouragement to embrace RFC 3339 - find out why!π Read
via "Naked Security".
Naked Security
How to deal with dates and times without any timezone tantrumsβ¦
Heartfelt encouragement to embrace RFC 3339 β find out why!
π’ UK, US condemn Iran for βunprecedentedβ cyber attack against Albania π’
π Read
via "ITPro".
The Balkan nation has cut ties with Iran following the hack, which took down national infrastructure and exposed government informationπ Read
via "ITPro".
IT PRO
UK, US condemn Iran for βunprecedentedβ cyber attack against Albania | IT PRO
The Balkan nation has cut ties with Iran following the hack, which took down national infrastructure and exposed government information
π’ DrayTek Vigor 2866ax review: Faster than you might expect π’
π Read
via "ITPro".
A versatile and very affordable SMB security router with Wi-Fi 6 and top-notch WAN redundancyπ Read
via "ITPro".
IT PRO
DrayTek Vigor 2866ax review: Faster than you might expect | IT PRO
A versatile and very affordable SMB security router with Wi-Fi 6 and top-notch WAN redundancy
π’ Thoma Bravo pulls plug on Darktrace takeover π’
π Read
via "ITPro".
Shares in the UK cyber firm slumped 30%, as investors had pinned hopes on takeover dealπ Read
via "ITPro".
IT PRO
Thoma Bravo pulls plug on Darktrace takeover | IT PRO
Shares in the UK cyber firm slumped 30%, as investors had pinned hopes on takeover deal
π’ HP patches high-severity security flaw in its own support tool π’
π Read
via "ITPro".
The application that's installed in every HP desktop and notebook was allowing hackers to elevate privileges through a DLL hijacking vulnerabilityπ Read
via "ITPro".
IT PRO
HP patches high-severity security flaw in its own support tool | IT PRO
The application that's installed in every HP desktop and notebook was allowing hackers to elevate privileges through a DLL hijacking vulnerability