βΌ CVE-2022-3199 βΌ
π Read
via "National Vulnerability Database".
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40784 βΌ
π Read
via "National Vulnerability Database".
Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3075 βΌ
π Read
via "National Vulnerability Database".
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40044 βΌ
π Read
via "National Vulnerability Database".
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40043 βΌ
π Read
via "National Vulnerability Database".
Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3201 βΌ
π Read
via "National Vulnerability Database".
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3200 βΌ
π Read
via "National Vulnerability Database".
Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3272 βΌ
π Read
via "National Vulnerability Database".
Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30003 βΌ
π Read
via "National Vulnerability Database".
Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3290 βΌ
π Read
via "National Vulnerability Database".
Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3298 βΌ
π Read
via "National Vulnerability Database".
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39258 βΌ
π Read
via "National Vulnerability Database".
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a phishing page to steal other information. The issue has been fixed with the 2022-09 mailcow Mootember Update. As a workaround, one may delete the Swapper API Documentation from their e-mail server.π Read
via "National Vulnerability Database".
π1
π Suricata IDPE 6.0.7 π
π Read
via "Packet Storm Security".
Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.π Read
via "Packet Storm Security".
Packetstormsecurity
Suricata IDPE 6.0.7 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
βΌ CVE-2022-39256 βΌ
π Read
via "National Vulnerability Database".
Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. This issue is patched in C1 CMS v6.13. There are no known workarounds.π Read
via "National Vulnerability Database".
β WhatsApp βzero-day exploitβ news scare β what you need to know β
π Read
via "Naked Security".
Is WhatsApp currently under active attack by cyercriminals? Is this a clear and current danger? How worried should WhatsApp users be?π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π3
βΌ CVE-2021-27854 βΌ
π Read
via "National Vulnerability Database".
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.π Read
via "National Vulnerability Database".
βΌ CVE-2021-27862 βΌ
π Read
via "National Vulnerability Database".
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).π Read
via "National Vulnerability Database".
βΌ CVE-2021-27861 βΌ
π Read
via "National Vulnerability Database".
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)π Read
via "National Vulnerability Database".
βΌ CVE-2021-27853 βΌ
π Read
via "National Vulnerability Database".
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.π Read
via "National Vulnerability Database".
βΌ CVE-2022-37346 βΌ
π Read
via "National Vulnerability Database".
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39835 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat.π Read
via "National Vulnerability Database".