βΌ CVE-2023-20615 βΌ
π Read
via "National Vulnerability Database".
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629572; Issue ID: ALPS07629572.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20608 βΌ
π Read
via "National Vulnerability Database".
In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0149 βΌ
π Read
via "National Vulnerability Database".
The WordPrezi WordPress plugin through 0.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacksπ Read
via "National Vulnerability Database".
βΌ CVE-2023-20612 βΌ
π Read
via "National Vulnerability Database".
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629571; Issue ID: ALPS07629571.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20616 βΌ
π Read
via "National Vulnerability Database".
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560720.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20610 βΌ
π Read
via "National Vulnerability Database".
In display drm, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363469; Issue ID: ALPS07363469.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0096 βΌ
π Read
via "National Vulnerability Database".
The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20614 βΌ
π Read
via "National Vulnerability Database".
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628615; Issue ID: ALPS07628615.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0669 βΌ
π Read
via "National Vulnerability Database".
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20611 βΌ
π Read
via "National Vulnerability Database".
In gpu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588678; Issue ID: ALPS07588678.π Read
via "National Vulnerability Database".
βΌ CVE-2023-20607 βΌ
π Read
via "National Vulnerability Database".
In ccu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07512839; Issue ID: ALPS07512839.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23944 βΌ
π Read
via "National Vulnerability Database".
Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were stored in cleartext in the database during the duration of OAuth2 setup procedure. Any attacker or malicious user with access to the database would have access to these user passwords until the OAuth setup has been completed. It is recommended that the Nextcloud Mail app is upgraded to 2.2.2. There are no known workarounds for this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0687 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0174 βΌ
π Read
via "National Vulnerability Database".
The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32655 βΌ
π Read
via "National Vulnerability Database".
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705028; Issue ID: GN20220705028.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0081 βΌ
π Read
via "National Vulnerability Database".
The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.π Read
via "National Vulnerability Database".
π΄ Cadien Cyber Response Launches to Deliver Incident Response & Complex Digital Forensics Services π΄
π Read
via "Dark Reading".
π Read
via "Dark Reading".
Dark Reading
Cadien Cyber Response Launches to Deliver Incident Response & Complex Digital Forensics Services
TYSONS, Va.--(BUSINESS WIRE)-- Cadien Cyber Response, a US-based incident response and complex digital forensics firm, formally launched operations today and unveiled its team of leading industry and government cyber experts focused on reactive services.
π΄ Global Ransomware Attack on VMware EXSi Hypervisors Continues to Spread π΄
π Read
via "Dark Reading".
The fresh "ESXiArgs" malware is exploiting a 2-year-old RCE security vulnerability (tracked as CVE-2021-21974), resulting in thousands of unpatched servers falling prey to the campaign.π Read
via "Dark Reading".
Dark Reading
Global Ransomware Attack on VMware EXSi Hypervisors Continues to Spread
The fresh "ESXiArgs" malware is exploiting a 2-year-old RCE security vulnerability (tracked as CVE-2021-21974), resulting in thousands of unpatched servers falling prey to the campaign.
π₯1
π΄ Consumer Watchdog Reports: CA Privacy Board OKs Landmark Personal Data Regulations, Some Key Protections Left Out π΄
π Read
via "Dark Reading".
π Read
via "Dark Reading".
Dark Reading
Consumer Watchdog Reports: CA Privacy Board OKs Landmark Personal Data Regulations, Some Key Protections Left Out
LOS ANGELES, Feb. 6, 2023 /PRNewswire/ -- After nearly a year of rulemaking and over 1,000 pages of public comments later, the country's first dedicated data privacy agency on Friday approved regulations aimed at giving consumers unprecedented control overβ¦
π΄ Crypto Drainers Are Ready to Ransack Investor Wallets π΄
π Read
via "Dark Reading".
Cryptocurrency drainers are the latest hot ticket being used in a string of lucrative cyberattacks aimed at virtual currency investors.π Read
via "Dark Reading".
Dark Reading
Crypto Drainers Are Ready to Ransack Investor Wallets
Cryptocurrency drainers are the latest hot ticket being used in a string of lucrative cyberattacks aimed at virtual currency investors.
βΌ CVE-2022-48311 βΌ
π Read
via "National Vulnerability Database".
**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.π Read
via "National Vulnerability Database".