🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Bfore.Ai Releases 'The King, The Knight & The Snowball' - Cybersecurity Book for Children 🕴

This unique fairytale is available for free just before Christmas to enjoy with the entire family.

📖 Read

via "Dark Reading".
‼ CVE-2022-46316 ‼

A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46314 ‼

The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46321 ‼

The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-43382 ‼

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46324 ‼

Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41599 ‼

The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46327 ‼

Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46318 ‼

The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46317 ‼

The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46310 ‼

The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-39166 ‼

IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force ID: 235405.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46325 ‼

Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46319 ‼

Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-38733 ‼

OnCommand Insight versions 7.3.1 through 7.3.14 are susceptible to an authentication bypass vulnerability in the Data Warehouse component.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46856 ‼

The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41596 ‼

The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-41590 ‼

Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46320 ‼

The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-23542 ‼

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-46313 ‼

The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.

📖 Read

via "National Vulnerability Database".