βΌ CVE-2023-30053 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29939 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr).π Read
via "National Vulnerability Database".
βΌ CVE-2023-29941 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29933 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30243 βΌ
π Read
via "National Vulnerability Database".
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30434 βΌ
π Read
via "National Vulnerability Database".
IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29942 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30013 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30054 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38707 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.π Read
via "National Vulnerability Database".
β S3 Ep133: Apple takes βtight-lippedβ to a whole new level β
π Read
via "Naked Security".
Entertaining, educational, and all in plain English π§ππ Read
via "Naked Security".
Naked Security
S3 Ep133: Apple takes βtight-lippedβ to a whole new level
Entertaining, educational, and all in plain English π§π
β World Password Day: 2 + 2 = 4 β
π Read
via "Naked Security".
We've kept it short and simple, with no sermons, no judgmentalism, no tubthumping... and no BUY NOW buttons. Have a nice day!π Read
via "Naked Security".
Naked Security
World Password Day: 2 + 2 = 4
Weβve kept it short and simple, with no sermons, no judgmentalism, no tubthumpingβ¦ and no BUY NOW buttons. Have a nice day!
β PHP Packagist supply chain poisoned by hacker βlooking for a jobβ β
π Read
via "Naked Security".
I pwned you! Gizza job! You know it makes sense!π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π΄ Attackers Route Malware Activity Over Popular CDNs π΄
π Read
via "Dark Reading".
One way to hide malicious activity is to make it look benign by blending in with regular traffic passing through content delivery networks (CDNs) and cloud service providers, according to a Netskope report.π Read
via "Dark Reading".
Dark Reading
Attackers Route Malware Activity Over Popular CDNs
One way to hide malicious activity is to make it look benign by blending in with regular traffic passing through content delivery networks (CDNs) and cloud service providers, according to a Netskope report.
βΌ CVE-2023-29659 βΌ
π Read
via "National Vulnerability Database".
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26285 βΌ
π Read
via "National Vulnerability Database".
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM X-Force ID: 248418.π Read
via "National Vulnerability Database".
βΌ CVE-2023-32269 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However, in order for an attacker to exploit this, the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability.π Read
via "National Vulnerability Database".
π΄ Apple Patches Bluetooth Flaw in AirPods, Beats π΄
π Read
via "Dark Reading".
Users can check for the updated firmware version of their wireless headphones in the Bluetooth settings of their iPhone, iPad, or Mac devices.π Read
via "Dark Reading".
Dark Reading
Apple Patches Bluetooth Flaw in AirPods, Beats
Users can check for the updated firmware version of their wireless headphones in the Bluetooth settings of their iPhone, iPad, or Mac devices.
π΄ Judge Spares Former Uber CISO Jail Time Over 2016 Data Breach Charges π΄
π Read
via "Dark Reading".
Tell other CISO's "you got a break," judge says in handing down a three-year probation sentence to Joseph Sullivan.π Read
via "Dark Reading".
Dark Reading
Judge Spares Former Uber CISO Jail Time Over 2016 Data Breach Charges
Tell other CISOs "you got a break," judge says in handing down a three-year probation sentence to Joseph Sullivan.
βΌ CVE-2023-2427 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.13.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4914 βΌ
π Read
via "National Vulnerability Database".
IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.π Read
via "National Vulnerability Database".