βΌ CVE-2023-24876 βΌ
π Read
via "National Vulnerability Database".
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24913 βΌ
π Read
via "National Vulnerability Database".
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24882 βΌ
π Read
via "National Vulnerability Database".
Microsoft OneDrive for Android Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24922 βΌ
π Read
via "National Vulnerability Database".
Microsoft Dynamics 365 Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24921 βΌ
π Read
via "National Vulnerability Database".
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24910 βΌ
π Read
via "National Vulnerability Database".
Windows Graphics Component Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-27069 βΌ
π Read
via "National Vulnerability Database".
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24906 βΌ
π Read
via "National Vulnerability Database".
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24911 βΌ
π Read
via "National Vulnerability Database".
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-27585 βΌ
π Read
via "National Vulnerability Database".
PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. A patch is available as commit `d1c5e4d` in the `master` branch. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23419 βΌ
π Read
via "National Vulnerability Database".
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-25206 βΌ
π Read
via "National Vulnerability Database".
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24909 βΌ
π Read
via "National Vulnerability Database".
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24930 βΌ
π Read
via "National Vulnerability Database".
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-24923 βΌ
π Read
via "National Vulnerability Database".
Microsoft OneDrive for Android Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-27070 βΌ
π Read
via "National Vulnerability Database".
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24919 βΌ
π Read
via "National Vulnerability Database".
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerabilityπ Read
via "National Vulnerability Database".
π’ MI5 to establish new security agency to counter Chinese hacking, espionage π’
π Read
via "ITPro".
The new organisation has been compared to GCHQβs NCSC, and will provide companies advice on how to deal with Chinese companies or carry out business in Chinaπ Read
via "ITPro".
ITPro
MI5 to establish new security agency to counter Chinese hacking, espionage
The new organisation has been compared to GCHQβs NCSC, and will provide companies advice on how to deal with Chinese companies or carry out business in China
βΌ CVE-2023-28144 βΌ
π Read
via "National Vulnerability Database".
KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls.π Read
via "National Vulnerability Database".
βΌ CVE-2023-27589 βΌ
π Read
via "National Vulnerability Database".
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created successfully, the root credential ceases to work appropriately. The issue is patched in RELEASE.2023-03-13T19-46-17Z. There are ways to work around this via adding higher privileges to the disabled root user via `mc admin policy set`.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28339 βΌ
π Read
via "National Vulnerability Database".
OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.π Read
via "National Vulnerability Database".