βΌ CVE-2015-10058 βΌ
π Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, was found in Wikisource Category Browser. This affects an unknown part of the file index.php. The manipulation of the argument lang leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is 764f4e8ce3f9242637df77530c70ae8a2ec4b6a1. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218415.π Read
via "National Vulnerability Database".
βΌ CVE-2015-10059 βΌ
π Read
via "National Vulnerability Database".
A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability affects unknown code of the file p05-integration/app/shared/api/apiService.js. The manipulation of the argument country/city leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 2aa760fa4e779e40a28206a32ac22ac10356f519. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218416.π Read
via "National Vulnerability Database".
π MIMEDefang Email Scanner 3.3 π
π Read
via "Packet Storm Security".
MIMEDefang is a flexible MIME email scanner designed to protect Windows clients from viruses. Includes the ability to do many other kinds of mail processing, such as replacing parts of messages with URLs. It can alter or delete various parts of a MIME message according to a very flexible configuration file. It can also bounce messages with unacceptable attachments. MIMEDefang works with the Sendmail 8.11 and newer "Milter" API, which makes it more flexible and efficient than procmail-based approaches.π Read
via "Packet Storm Security".
Packetstormsecurity
MIMEDefang Email Scanner 3.3 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
βΌ CVE-2023-0338 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.π Read
via "National Vulnerability Database".
βΌ CVE-2016-15021 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in nickzren alsdb. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. Upgrading to version v2 is able to address this issue. The name of the patch is cbc79a68145e845f951113d184b4de207c341599. It is recommended to upgrade the affected component. The identifier VDB-218429 was assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0337 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.π Read
via "National Vulnerability Database".
βΌ CVE-2013-10013 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in Bricco Authenticator Plugin. It has been declared as critical. This vulnerability affects the function authenticate/compare of the file src/java/talentum/escenic/plugins/authenticator/authenticators/DBAuthenticator.java. The manipulation leads to sql injection. Upgrading to version 1.39 is able to address this issue. The name of the patch is a5456633ff75e8f13705974c7ed1ce77f3f142d5. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218428.π Read
via "National Vulnerability Database".
βΌ CVE-2015-10061 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in evandro-machado Trabalho-Web2. It has been classified as critical. This affects an unknown part of the file src/java/br/com/magazine/dao/ClienteDAO.java. The manipulation leads to sql injection. The name of the patch is f59ac954625d0a4f6d34f069a2e26686a7a20aeb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218427.π Read
via "National Vulnerability Database".
β Multi-million investment scammers busted in four-country Europol raid β
π Read
via "Naked Security".
216 questioned, 15 arrested, 4 fake call centres searched, millions seized...π Read
via "Naked Security".
Naked Security
Multi-million investment scammers busted in four-country Europol raid
216 questioned, 15 arrested, 4 fake call centres searched, millions seizedβ¦
β Serious Security: Unravelling the LifeLock βhacked passwordsβ story β
π Read
via "Naked Security".
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
βΌ CVE-2022-3091 βΌ
π Read
via "National Vulnerability Database".
RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41861 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.π Read
via "National Vulnerability Database".
βΌ CVE-2022-4121 βΌ
π Read
via "National Vulnerability Database".
In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found that could lead to a remote denial of service or other potential consequences.π Read
via "National Vulnerability Database".
βΌ CVE-2018-14628 βΌ
π Read
via "National Vulnerability Database".
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.π Read
via "National Vulnerability Database".
βΌ CVE-2022-2893 βΌ
π Read
via "National Vulnerability Database".
RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41859 βΌ
π Read
via "National Vulnerability Database".
In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41860 βΌ
π Read
via "National Vulnerability Database".
In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.π Read
via "National Vulnerability Database".
βΌ CVE-2022-4621 βΌ
π Read
via "National Vulnerability Database".
Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allow an attacker to perform changes with administrator level privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0158 βΌ
π Read
via "National Vulnerability Database".
NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" endpoint. Prior to 0.12.1 a direct query for any existing directory under "/rrdp/", rather than an RRDP file such as "/rrdp/notification.xml" as would be expected, causes Krill to crash. If the built-in "/rrdp" endpoint is exposed directly to the internet, then malicious remote parties can cause the publication server to crash. The repository content is not affected by this, but the availability of the server and repository can cause issues if this attack is persistent and is not mitigated.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41858 βΌ
π Read
via "National Vulnerability Database".
A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.π Read
via "National Vulnerability Database".
βΌ CVE-2015-10064 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in VictorFerraresi pokemon-database-php. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The name of the patch is dd0e1e6cdf648d6a3deff441f515bcb1d7573d68. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218455.π Read
via "National Vulnerability Database".