βΌ CVE-2022-41802 βΌ
π Read
via "National Vulnerability Database".
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39903 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45523 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45501 βΌ
π Read
via "National Vulnerability Database".
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39915 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45511 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45499 βΌ
π Read
via "National Vulnerability Database".
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39902 βΌ
π Read
via "National Vulnerability Database".
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.π Read
via "National Vulnerability Database".
βΌ CVE-2022-4364 βΌ
π Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Teledyne FLIR AX8 up to 1.46.16. Affected is an unknown function of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-215118 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45506 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38754 βΌ
π Read
via "National Vulnerability Database".
A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the Operations Bridge Manager capability is deployed. A potential vulnerability has been identified in Micro Focus Operations Bridge Manager (OBM). The vulnerability could be exploited by a malicious authenticated OBM user to run Java Scripts in the browser context of another OBM user. This issue affects: Micro Focus Micro Focus Operations Bridge Manager versions prior to 2022.11. Micro Focus Micro Focus Operations Bridge- Containerized versions prior to 2022.11.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45505 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39904 βΌ
π Read
via "National Vulnerability Database".
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45508 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.π Read
via "National Vulnerability Database".
βΌ CVE-2022-4123 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45507 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45513 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45512 βΌ
π Read
via "National Vulnerability Database".
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39895 βΌ
π Read
via "National Vulnerability Database".
Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.π Read
via "National Vulnerability Database".
β Credit card skimming β the long and winding road of supply chain failure β
π Read
via "Naked Security".
Don't keep calling home to a JavaScript server that closed its doors eight years ago!π Read
via "Naked Security".
Naked Security
Credit card skimming β the long and winding road of supply chain failure
Donβt keep calling home to a JavaScript server that closed its doors eight years ago!
βοΈ New Ransom Payment Schemes Target Executives, Telemedicine βοΈ
π Read
via "Krebs on Security".
Ransomware groups are constantly devising new methods for infecting victims and convincing them to pay up, but a couple of strategies tested recently seem especially devious. The first centers on targeting healthcare organizations that offer consultations over the Internet and sending them booby-trapped medical records for the "patient." The other involves carefully editing email inboxes of public company executives to make it appear that some were involved in insider trading.π Read
via "Krebs on Security".
Krebs on Security
New Ransom Payment Schemes Target Executives, Telemedicine
Ransomware groups are constantly devising new methods for infecting victims and convincing them to pay up, but a couple of strategies tested recently seem especially devious. The first centers on targeting healthcare organizations that offer consultationsβ¦