πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-44249 β€Ό

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44254 β€Ό

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44255 β€Ό

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44257 β€Ό

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft: Popular IoT SDKs Leave Critical Infrastructure Wide Open to Cyberattack πŸ•΄

Chinese threat actors have already used the vulnerable and pervasive Boa server to infiltrate the electrical grid in India, in spate of malicious incidents.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Hot Ticket: 'Aurora' Go-Based InfoStealer Finds Favor Among Cyber-Threat Actors πŸ•΄

The infostealer Aurora’s low detection rates and newcomer status are helping it fly under the radar, as more cybercriminal gangs target cryptocurrency wallets and communications apps.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 'Patch Lag' Leaves Millions of Android Devices Vulnerable πŸ•΄

Months after a fix was issued by a vendor, downstream Android device manufacturers still haven't patched, highlighting a troubling trend.

πŸ“– Read

via "Dark Reading".
⚠ CryptoRom β€œpig butchering” scam sites seized, suspects arrested in US ⚠

Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2021-35284 β€Ό

SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41922 β€Ό

`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23740 β€Ό

CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub Actions. This vulnerability affected only version 3.7.0 of GitHub Enterprise Server and was fixed in version 3.7.1. This vulnerability was reported via the GitHub Bug Bounty program.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40772 β€Ό

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40304 β€Ό

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38113 β€Ό

This vulnerability discloses build and services versions in the server response header.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-35246 β€Ό

The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39833 β€Ό

FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35501 β€Ό

Stored Cross-site Scripting in Amasty Blog Pro 2.10.4 and 2.10.4 creates post functionality and lower versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36111 β€Ό

immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. This issue has been patched in version 1.4.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40771 β€Ό

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2009-1142 β€Ό

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38115 β€Ό

Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT

πŸ“– Read

via "National Vulnerability Database".