๐ด Student Medical Records Exposed After LAUSD Breach ๐ด
๐ Read
via "Dark Reading".
"Hundreds" of special education students' psych records have turned up on the Dark Web. School records like these are covered by FERPA, not HIPAA, so parents have little recourse.๐ Read
via "Dark Reading".
Dark Reading
Student Medical Records Exposed After LAUSD Breach
"Hundreds" of special education students' psych records have turned up on the Dark Web. School records like these are covered by FERPA, not HIPAA, so parents have little recourse.
๐ด Pirated Final Cut Pro for macOS Offers Stealth Malware Delivery ๐ด
๐ Read
via "Dark Reading".
The number of people who have made the weaponized software available for sharing via torrent suggests that many unsuspecting victims may have downloaded the XMRig coin miner.๐ Read
via "Dark Reading".
Dark Reading
Pirated Final Cut Pro for macOS Offers Stealth Malware Delivery
The number of people who have made the weaponized software available for sharing via torrent suggests that many unsuspecting victims may have downloaded the XMRig coin miner.
โผ CVE-2022-46785 โผ
๐ Read
via "National Vulnerability Database".
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46784 โผ
๐ Read
via "National Vulnerability Database".
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0755 โผ
๐ Read
via "National Vulnerability Database".
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25823 โผ
๐ Read
via "National Vulnerability Database".
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`), a private SSH key is sent to any user that connects to the Gradio machine, which means that a user could access other users' shared Gradio demos. From there, other exploits are possible depending on the level of access/exposure the Gradio app provides. This issue is patched in version 3.13.1, however, users are recommended to update to 3.19.1 or later where the FRP solution has been properly tested.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-36231 โผ
๐ Read
via "National Vulnerability Database".
pdf_info 0.5.3 is vulnerable to Command Execution.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25824 โผ
๐ Read
via "National Vulnerability Database".
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop retrying the read operation, consuming CPU resources. This could be exploited for denial of service attacks. If trace level logging was enabled, it would also produce an excessive amount of log output during the loop, consuming disk space. The problem has been fixed in commit d7eec4e598158ab6a98bf505354e84352f9715ec, please update to version 0.12.1. There are no workarounds, users who cannot update should apply the errno fix detailed in the security advisory.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0754 โผ
๐ Read
via "National Vulnerability Database".
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24205 โผ
๐ Read
via "National Vulnerability Database".
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).๐ Read
via "National Vulnerability Database".
๐ด 87% of Container Images in Production Have Critical or High-Severity Vulnerabilities ๐ด
๐ Read
via "Dark Reading".
At the inaugural CloudNativeSecurityCon, DevSecOps practitioners discussed how to shore up the software supply chain.๐ Read
via "Dark Reading".
Dark Reading
87% of Container Images in Production Have Critical or High-Severity Vulnerabilities
At the inaugural CloudNativeSecurityCon, DevSecOps practitioners discussed how to shore up the software supply chain.
โผ CVE-2023-24212 โผ
๐ Read
via "National Vulnerability Database".
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23295 โผ
๐ Read
via "National Vulnerability Database".
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23296 โผ
๐ Read
via "National Vulnerability Database".
Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26468 โผ
๐ Read
via "National Vulnerability Database".
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23294 โผ
๐ Read
via "National Vulnerability Database".
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.๐ Read
via "National Vulnerability Database".
๐ฅ1
โผ CVE-2023-26102 โผ
๐ Read
via "National Vulnerability Database".
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46440 โผ
๐ Read
via "National Vulnerability Database".
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0995 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-1607 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) รขโฌโ comcode 150047415.๐ Read
via "National Vulnerability Database".
โค1
โผ CVE-2023-0994 โผ
๐ Read
via "National Vulnerability Database".
Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.๐ Read
via "National Vulnerability Database".