🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-41404 ‼

An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41385 ‼

The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42041 ‼

The d8s-file-system package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42036 ‼

The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42042 ‼

The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41384 ‼

The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42038 ‼

The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42037 ‼

The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42040 ‼

The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42039 ‼

The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42044 ‼

The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41382 ‼

The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41387 ‼

The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41383 ‼

The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41381 ‼

The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42717 ‼

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-42043 ‼

The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41386 ‼

The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41550 ‼

GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-37617 ‼

Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.

📖 Read

via "National Vulnerability Database".
📢 The best TeamViewer alternatives 📢

These remote desktop software tools are feature-packed TeamViewer alternatives that can help you save money

📖 Read

via "ITPro".