πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-47093 β€Ό

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47656 β€Ό

GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47663 β€Ό

GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47088 β€Ό

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47655 β€Ό

Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47087 β€Ό

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47086 β€Ό

GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47660 β€Ό

GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4378 β€Ό

A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

πŸ“– Read

via "National Vulnerability Database".
⚠ Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches ⚠

Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

πŸ“– Read

via "Naked Security".
⚠ S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text] ⚠

Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)

πŸ“– Read

via "Naked Security".
πŸ•΄ Bluebottle Continues Bank Heist Assault With Signed Malware πŸ•΄

The financially motivated threat group, also known as OPERA1ER, demonstrated an evolution in tactics in its compromise of three Francophone financial institutions in Africa, likely adding to its $11 million to-date haul.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-43573 β€Ό

IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4434 β€Ό

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43844 β€Ό

IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4435 β€Ό

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4432 β€Ό

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0086 β€Ό

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due to missing nonce validation on the save() function. This makes it possible for unauthenticated attackers to to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can be used to enable SVG uploads that could make Cross-Site Scripting possible.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4433 β€Ό

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46168 β€Ό

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users inside the group SMTP topic. Most of the time this is not an issue as they are likely already familiar with one another's email addresses. This issue is patched in versions 2.8.14 and 2.9.0.beta15. The fix is that someone sending emails out via group SMTP to non-staged users masks those emails with blind carbon copy (BCC). Staged users are ones that have likely only interacted with the group via email, and will likely include other people who were CC'd on the original email to the group. As a workaround, disable group SMTP for any groups that have it enabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41740 β€Ό

IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtain highly sensitive information from system memory. IBM X-Force ID: 238053.

πŸ“– Read

via "National Vulnerability Database".