βΌ CVE-2023-25415 βΌ
π Read
via "National Vulnerability Database".
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24931 βΌ
π Read
via "National Vulnerability Database".
Windows Secure Channel Denial of Service Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-26551 βΌ
π Read
via "National Vulnerability Database".
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop.π Read
via "National Vulnerability Database".
βΌ CVE-2023-22808 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28808 βΌ
π Read
via "National Vulnerability Database".
Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28226 βΌ
π Read
via "National Vulnerability Database".
Windows Enroll Engine Security Feature Bypass Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28255 βΌ
π Read
via "National Vulnerability Database".
Windows DNS Server Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28301 βΌ
π Read
via "National Vulnerability Database".
Microsoft Edge (Chromium-based) Tampering Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28271 βΌ
π Read
via "National Vulnerability Database".
Windows Kernel Memory Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28299 βΌ
π Read
via "National Vulnerability Database".
Visual Studio Spoofing Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28300 βΌ
π Read
via "National Vulnerability Database".
Azure Service Connector Security Feature Bypass Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28237 βΌ
π Read
via "National Vulnerability Database".
Windows Kernel Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28243 βΌ
π Read
via "National Vulnerability Database".
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-23375 βΌ
π Read
via "National Vulnerability Database".
Microsoft ODBC and OLE DB Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-28311 βΌ
π Read
via "National Vulnerability Database".
Microsoft Word Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βοΈ Microsoft (& Apple) Patch Tuesday, April 2023 Edition βοΈ
π Read
via "Krebs on Security".
Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones, iPads and Macs.π Read
via "Krebs on Security".
Krebs on Security
Microsoft (& Apple) Patch Tuesday, April 2023 Edition
Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set ofβ¦
βΌ CVE-2023-22613 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.π Read
via "National Vulnerability Database".
β Attention gamers! Motherboard maker MSI admits to breach, issues βrogue firmwareβ alert β
π Read
via "Naked Security".
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.π Read
via "Naked Security".
Naked Security
Attention gamers! Motherboard maker MSI admits to breach, issues βrogue firmwareβ alert
Stealing private keys is like getting hold of a medieval monarchβs personal signet ringβ¦ you get to put an official seal on treasonous material.
βΌ CVE-2022-48437 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30512 βΌ
π Read
via "National Vulnerability Database".
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.π Read
via "National Vulnerability Database".