βΌ CVE-2022-3506 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41715 βΌ
π Read
via "National Vulnerability Database".
Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42066 βΌ
π Read
via "National Vulnerability Database".
Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42463 βΌ
π Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42071 βΌ
π Read
via "National Vulnerability Database".
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28761 βΌ
π Read
via "National Vulnerability Database".
Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42464 βΌ
π Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive information including kernel pointer, which could be used in further attacks. The processes with system user UID run on the device would be able to mmap memory pools used by kernel and override them which could be used to gain kernel code execution on the device, gain root privileges, or cause device reboot.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3504 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affects some unknown processing of the file /php-sms/?p=services/view_service. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210839.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32149 βΌ
π Read
via "National Vulnerability Database".
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42064 βΌ
π Read
via "National Vulnerability Database".
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42488 βΌ
π Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2879 βΌ
π Read
via "National Vulnerability Database".
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.π Read
via "National Vulnerability Database".
βΌ CVE-2022-42070 βΌ
π Read
via "National Vulnerability Database".
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).π Read
via "National Vulnerability Database".
βΌ CVE-2022-41686 βΌ
π Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.π Read
via "National Vulnerability Database".
β S3 Ep104: Should hospital ransomware attackers be locked up for life? [Audio + Text] β
π Read
via "Naked Security".
Have your say on three deep questions posed by this week's podcast. Read or listen as suits you best...π Read
via "Naked Security".
Naked Security
S3 Ep104: Should hospital ransomware attackers be locked up for life? [Audio + Text]
Have your say on three deep questions posed by this weekβs podcast. Read or listen as suits you bestβ¦
β Serious Security: Microsoft Office 365 attacked over feeble encryption β
π Read
via "Naked Security".
How 2022 is your encryption?π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π΄ Fast Fashion Retailer Data Breach Draws $1.9M Fine π΄
π Read
via "Dark Reading".
New York AG fines Shein and Romwe parent company for failure to protect customer data and downplaying the 2018 compromise of 46 million shopper records.π Read
via "Dark Reading".
Dark Reading
Fast Fashion Retailer Data Breach Draws $1.9M Fine
New York AG fines Shein and Romwe parent company for failure to protect customer data and downplaying the 2018 compromise of 46 million shopper records.
βΌ CVE-2022-41307 βΌ
π Read
via "National Vulnerability Database".
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41306 βΌ
π Read
via "National Vulnerability Database".
A maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41586 βΌ
π Read
via "National Vulnerability Database".
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41582 βΌ
π Read
via "National Vulnerability Database".
The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.π Read
via "National Vulnerability Database".