πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ β€˜We don’t teach developers how to write secure software’ – Linux Foundation’s David A Wheeler on reversing the CVE surge πŸ—“οΈ

Teach devs security fundamentals to bolster supply chain resilience, argues Wheeler Addressing a decades-old deficiency in coding curriculums could have a profound effect on the security of the softwa

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Acuity Reports Increase in Cyber Liability Insurance Claims as Cybercrime Skyrockets πŸ•΄

Acuity Insurance reports ongoing increased insurance risk for individuals and businesses.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft 365 Message Encryption Can Leak Sensitive Info πŸ•΄

The default email encryption used in Microsoft Office's cloud version is leaky, which the company acknowledged but said it wouldn't fix.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-42069 β€Ό

Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28760 β€Ό

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3505 β€Ό

A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210840.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28762 β€Ό

Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local malicious user could use this debugging port to connect to and control the Zoom Apps running in the Zoom client.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28759 β€Ό

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2880 β€Ό

Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparseable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparseable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3506 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41715 β€Ό

Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42066 β€Ό

Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42463 β€Ό

OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42071 β€Ό

Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28761 β€Ό

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42464 β€Ό

OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive information including kernel pointer, which could be used in further attacks. The processes with system user UID run on the device would be able to mmap memory pools used by kernel and override them which could be used to gain kernel code execution on the device, gain root privileges, or cause device reboot.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3504 β€Ό

A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affects some unknown processing of the file /php-sms/?p=services/view_service. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210839.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32149 β€Ό

An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42064 β€Ό

Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42488 β€Ό

OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2879 β€Ό

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

πŸ“– Read

via "National Vulnerability Database".