πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-42064 β€Ό

Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42488 β€Ό

OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2879 β€Ό

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42070 β€Ό

Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41686 β€Ό

OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep104: Should hospital ransomware attackers be locked up for life? [Audio + Text] ⚠

Have your say on three deep questions posed by this week's podcast. Read or listen as suits you best...

πŸ“– Read

via "Naked Security".
⚠ Serious Security: Microsoft Office 365 attacked over feeble encryption ⚠

How 2022 is your encryption?

πŸ“– Read

via "Naked Security".
πŸ•΄ Fast Fashion Retailer Data Breach Draws $1.9M Fine πŸ•΄

New York AG fines Shein and Romwe parent company for failure to protect customer data and downplaying the 2018 compromise of 46 million shopper records.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-41307 β€Ό

A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41306 β€Ό

A maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41586 β€Ό

The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41582 β€Ό

The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38980 β€Ό

The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39011 β€Ό

The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0699 β€Ό

In HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-242345178

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20464 β€Ό

In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-236042696References: N/A

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41600 β€Ό

The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39065 β€Ό

A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÃ…DFRI gateway unresponsive, such that connected lighting cannot be controlled with the IKEA Home Smart app and TRÃ…DFRI remote control. The malformed Zigbee frame is an unauthenticated broadcast message, which means all vulnerable devices within radio range are affected. CVSS 3.1 Base Score: 6.5 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-22685 β€Ό

An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41594 β€Ό

The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41578 β€Ό

The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.

πŸ“– Read

via "National Vulnerability Database".