πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-40152 β€Ό

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40153 β€Ό

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40151 β€Ό

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40149 β€Ό

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3223 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40156 β€Ό

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40150 β€Ό

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40155 β€Ό

Those using Xstream to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Packet Fence 12.0.0 πŸ› 

PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.

πŸ“– Read

via "Packet Storm Security".
πŸ” Friday Five 9/16 πŸ”

Twitter’s security scandal going from bad to worse and malware spreading through YouTube made headlines this week. Read about these stories and more in this week’s Friday Five!


πŸ“– Read

via "".
πŸ—“οΈ Uber hack linked to hardcoded secrets spotted in powershell script πŸ—“οΈ

Social engineering attack compromises internal networks and Uber’s bug bounty reports

πŸ“– Read

via "The Daily Swig".
⚠ UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you ⚠

Uber is all over the news for a widely-publicised data breach. We help you answer the question, "How do I stop this happening to me?"

πŸ“– Read

via "Naked Security".
πŸ—“οΈ NETGEAR resolves router vulnerabilities in bundled gaming component πŸ—“οΈ

Silicon Valley vendor tackles command injection and MitM-to-RCE issues

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-38828 β€Ό

TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37250 β€Ό

Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38833 β€Ό

School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-38846 β€Ό

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38843 β€Ό

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38823 β€Ό

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38808 β€Ό

ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38827 β€Ό

TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi

πŸ“– Read

via "National Vulnerability Database".