๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2022-46784 โ€ผ

SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-0755 โ€ผ

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25823 โ€ผ

Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`), a private SSH key is sent to any user that connects to the Gradio machine, which means that a user could access other users' shared Gradio demos. From there, other exploits are possible depending on the level of access/exposure the Gradio app provides. This issue is patched in version 3.13.1, however, users are recommended to update to 3.19.1 or later where the FRP solution has been properly tested.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36231 โ€ผ

pdf_info 0.5.3 is vulnerable to Command Execution.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25824 โ€ผ

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop retrying the read operation, consuming CPU resources. This could be exploited for denial of service attacks. If trace level logging was enabled, it would also produce an excessive amount of log output during the loop, consuming disk space. The problem has been fixed in commit d7eec4e598158ab6a98bf505354e84352f9715ec, please update to version 0.12.1. There are no workarounds, users who cannot update should apply the errno fix detailed in the security advisory.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-0754 โ€ผ

The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24205 โ€ผ

Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด 87% of Container Images in Production Have Critical or High-Severity Vulnerabilities ๐Ÿ•ด

At the inaugural CloudNativeSecurityCon, DevSecOps practitioners discussed how to shore up the software supply chain.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-24212 โ€ผ

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23295 โ€ผ

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23296 โ€ผ

Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26468 โ€ผ

Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23294 โ€ผ

Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ”ฅ1
โ€ผ CVE-2023-26102 โ€ผ

All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-46440 โ€ผ

ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-0995 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-1607 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) รขโ‚ฌโ€œ comcode 150047415.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2023-0994 โ€ผ

Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-0996 โ€ผ

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1005 โ€ผ

A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-221738 is the identifier assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-0999 โ€ผ

A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221734 is the identifier assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".