โผ CVE-2022-4689 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4684 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4683 โผ
๐ Read
via "National Vulnerability Database".
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4686 โผ
๐ Read
via "National Vulnerability Database".
Improper Authentication in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4687 โผ
๐ Read
via "National Vulnerability Database".
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4685 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4688 โผ
๐ Read
via "National Vulnerability Database".
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4690 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.๐ Read
via "National Vulnerability Database".
๐ GRAudit Grep Auditing Tool 3.5 ๐
๐ Read
via "Packet Storm Security".
Graudit is a simple script and signature sets that allows you to find potential security flaws in source code using the GNU utility, grep. It's comparable to other static analysis applications like RATS, SWAAT, and flaw-finder while keeping the technical requirements to a minimum and being very flexible.๐ Read
via "Packet Storm Security".
Packetstormsecurity
GRAudit Grep Auditing Tool 3.5 โ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
โผ CVE-2022-47524 โผ
๐ Read
via "National Vulnerability Database".
F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46171 โผ
๐ Read
via "National Vulnerability Database".
Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected. The issue has been patched in the latest release and was backported into the currently supported 1.x branches. There are no known workarounds at the time of publication.๐ Read
via "National Vulnerability Database".
๐ด Fool Me Thrice? How to Avoid Double and Triple Ransomware Extortion ๐ด
๐ Read
via "Dark Reading".
To stay safer, restrict access to data, monitor for breaches in the supply chain, track relevant data that is sold on the Dark Web, and implement best safety practices.๐ Read
via "Dark Reading".
Dark Reading
Fool Me Thrice? How to Avoid Double and Triple Ransomware Extortion
To stay safer, restrict access to data, monitor for breaches in the supply chain, track relevant data that is sold on the Dark Web, and implement best safety practices.
๐ด Google: With Cloud Comes APIs & Security Headaches ๐ด
๐ Read
via "Dark Reading".
APIs are key to cloud transformation, but two Google surveys find that cyberattacks targeting them are reaching a tipping point, even as general cloud security issues abound.๐ Read
via "Dark Reading".
Dark Reading
Google: With Cloud Comes APIs & Security Headaches
APIs are key to cloud transformation, but two Google surveys find that cyberattacks targeting them are reaching a tipping point, even as general cloud security issues abound.
๐2
โผ CVE-2022-47941 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in ksmbd in the Linux kernel before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.๐ Read
via "National Vulnerability Database".
๐1
โผ CVE-2022-43551 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request, it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.๐ Read
via "National Vulnerability Database".
๐1
โผ CVE-2022-4698 โผ
๐ Read
via "National Vulnerability Database".
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-47942 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in ksmbd in the Linux kernel before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46642 โผ
๐ Read
via "National Vulnerability Database".
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4697 โผ
๐ Read
via "National Vulnerability Database".
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the รขโฌหwp_user_cover_default_image_urlรขโฌโข parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-44565 โผ
๐ Read
via "National Vulnerability Database".
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-44567 โผ
๐ Read
via "National Vulnerability Database".
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), which may lead to remote code execution (internalVideoChatWindow.ts#L17). To exploit the vulnerability, the internal video chat window must be disabled or a Mac App Store build must be used (internalVideoChatWindow.ts#L14). The vulnerability may be exploited by an XSS attack because the function openInternalVideoChatWindow is exposed in the Rocket.Chat-Desktop-API.๐ Read
via "National Vulnerability Database".