βΌ CVE-2023-24977 βΌ
π Read
via "National Vulnerability Database".
Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 https://github.com/apache/inlong/pull/7214 to solve it.π Read
via "National Vulnerability Database".
βΌ CVE-2021-3808 βΌ
π Read
via "National Vulnerability Database".
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.π Read
via "National Vulnerability Database".
βΌ CVE-2022-46756 βΌ
π Read
via "National Vulnerability Database".
Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the container's underlying OS. Exploitation may lead to a system take over by an attacker.π Read
via "National Vulnerability Database".
β€1
βΌ CVE-2021-3809 βΌ
π Read
via "National Vulnerability Database".
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45098 βΌ
π Read
via "National Vulnerability Database".
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45102 βΌ
π Read
via "National Vulnerability Database".
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary \u2018Host\u2019 header values to poison a web cache or trigger redirections.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32482 βΌ
π Read
via "National Vulnerability Database".
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.π Read
via "National Vulnerability Database".
βΌ CVE-2022-46679 βΌ
π Read
via "National Vulnerability Database".
Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27538 βΌ
π Read
via "National Vulnerability Database".
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.π Read
via "National Vulnerability Database".
π’ US extradites French ShinyHunters hacker, faces 123 years in prison π’
π Read
via "ITPro".
The hacker is believed to be a member of the hacking group known for its spree of data breaches across 2020 and 2021π Read
via "ITPro".
ITPro
US extradites French ShinyHunters hacker, faces 123 years in prison
The hacker is believed to be a member of the hacking group known for its spree of data breaches across 2020 and 2021
π’ The IT Pro Podcast: The problem with APIs π’
π Read
via "ITPro".
With API attacks on the rise, knowing your attack surface is crucialπ Read
via "ITPro".
ITPro
The IT Pro Podcast: The problem with APIs
With API attacks on the rise, knowing your attack surface is crucial
π’ Podcast transcript: The problem with APIs π’
π Read
via "ITPro".
Read the full transcript for this episode of the IT Pro Podcastπ Read
via "ITPro".
ITPro
Podcast transcript: The problem with APIs
Read the full transcript for this episode of the IT Pro Podcast
ποΈ Researcher drops Lexmark RCE zero-day rather than sell vuln βfor peanutsβ ποΈ
π Read
via "The Daily Swig".
Printer exploit chain could be weaponized to fully compromise more than 100 modelsπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Researcher drops Lexmark RCE zero-day rather than sell vuln βfor peanutsβ
Printer exploit chain could be weaponized to fully compromise more than 100 models
βΌ CVE-2023-0610 βΌ
π Read
via "National Vulnerability Database".
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0609 βΌ
π Read
via "National Vulnerability Database".
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.π Read
via "National Vulnerability Database".
π΄ Google Fi Users Caught Up in T-Mobile Breach π΄
π Read
via "Dark Reading".
Google Fi mobile customers have been alerted that their SIM card serial numbers, phone numbers, and other data were exposed in T-Mobile hack.π Read
via "Dark Reading".
Dark Reading
Google Fi Users Caught Up in T-Mobile Breach
Google Fi mobile customers have been alerted that their SIM card serial numbers, phone numbers, and other data were exposed in T-Mobile hack.
βΌ CVE-2022-47717 βΌ
π Read
via "National Vulnerability Database".
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).π Read
via "National Vulnerability Database".
βΌ CVE-2023-23127 βΌ
π Read
via "National Vulnerability Database".
In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS.π Read
via "National Vulnerability Database".
βΌ CVE-2022-47002 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.π Read
via "National Vulnerability Database".
βΌ CVE-2023-22575 βΌ
π Read
via "National Vulnerability Database".
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2022-47714 βΌ
π Read
via "National Vulnerability Database".
Last Yard 22.09.8-1 does not enforce HSTS headersπ Read
via "National Vulnerability Database".