πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23768 β€Ό

This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28204 β€Ό

A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23767 β€Ό

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victimÒ€ℒs system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23766 β€Ό

An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35066 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35069 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b544e.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35063 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41a8.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35061 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e412a.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38550 β€Ό

A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35070 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x65fc97.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35060 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0a32.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35064 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adcdb in __asan_memset.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28321 β€Ό

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35065 β€Ό

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x65f724.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38545 β€Ό

Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38509 β€Ό

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38532 β€Ό

Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows attackers to escalate privileges via running a crafted executable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35062 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0bc3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38527 β€Ό

UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35068 β€Ό

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e420d.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0143 β€Ό

When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)

πŸ“– Read

via "National Vulnerability Database".