πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-29579 β€Ό

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48477 β€Ό

In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48476 β€Ό

In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29578 β€Ό

mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty() function at src/mp4property.cpp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29583 β€Ό

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29582 β€Ό

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The New Frontier in Email Security: Goodbye, Gateways; Hello, Behavioral AI πŸ•΄

As email attackers move to more targeted and sophisticated attacks, email security needs to understand the organization, not past attacks, to keep up with attacker innovation and stop novel threats on the first encounter.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity Survival: Hide From Adversarial AI πŸ•΄

Consider adding some security-through-obscurity tactics to your organization's protection arsenal to boost protection. Mask your attack surface behind additional zero-trust layers to remove AI's predictive advantage.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ZeroFox to Acquire LookingGlass, Broadening Global Attack Surface Intelligence Capabilities πŸ•΄

Deal strengthens ZeroFox's External Cybersecurity Platform with attack surface management (EASM) and threat intelligence capabilities.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-47598 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Plugins Pro WP Super Popup pluginΓ‚ <= 1.1.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1731 β€Ό

In LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2251 β€Ό

Uncaught Exception in GitHub repository eemeli/yaml prior to 2.2.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23892 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jamie Poitra M Chart plugin <=Γ‚ 1.9.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24819 β€Ό

RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The overflow can be used to corrupt other packets and the allocator metadata. Corrupting a pointer will easily lead to denial of service. While carefully manipulating the allocator metadata gives an attacker the possibility to write data to arbitrary locations and thus execute arbitrary code. Version 2022.10 fixes this issue. As a workaround, disable support for fragmented IP datagrams or apply the patches manually.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29849 β€Ό

Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30370 β€Ό

In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24820 β€Ό

RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. An attacker can send a crafted frame to the device resulting in a large out of bounds write beyond the packet buffer. The write will create a hard fault exception after reaching the last page of RAM. The hard fault is not handled and the system will be stuck until reset. Thus the impact is denial of service. Version 2022.10 fixes this issue. As a workaround, apply the patch manually.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30368 β€Ό

Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30376 β€Ό

In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29480 β€Ό

Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.

πŸ“– Read

via "National Vulnerability Database".