🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2023-24948 ‼

Windows Bluetooth Driver Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46749 ‼

Insufficient bounds checking in ASP (AMD SecureProcessor) may allow for an out of bounds read in SMI (System ManagementInterface) mailbox checksum calculation triggering a data abort, resulting in apotential denial of service.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24898 ‼

Windows SMB Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-26406 ‼

Insufficient validation in parsing Owner'sCertificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization)and SEV-ES user application can lead to a host crash potentially resulting indenial of service.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24941 ‼

Windows Network File System Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24900 ‼

Windows NTLM Security Support Provider Information Disclosure Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24950 ‼

Microsoft SharePoint Server Spoofing Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-26354 ‼

Insufficient bounds checking in ASP may allow anattacker to issue a system call from a compromised ABL which may causearbitrary memory values to be initialized to zero, potentially leading to aloss of integrity.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20520 ‼

Improper access control settings in ASPBootloader may allow an attacker to corrupt the return address causing astack-based buffer overrun potentially leading to arbitrary code execution.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46763 ‼

Insufficient input validation in the SMU mayenable a privileged attacker to write beyond the intended bounds of a sharedmemory buffer potentially leading to a loss of integrity.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20524 ‼

An attacker with a compromised ASP couldpossibly send malformed commands to an ASP on another CPU, resulting in an outof bounds write, potentially leading to a loss a loss of integrity.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-26356 ‼

A TOCTOU in ASP bootloader may allow an attackerto tamper with the SPI ROM following data read to memory potentially resultingin S3 data corruption and information disclosure.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-26397 ‼

Insufficient address validation, may allow anattacker with a compromised ABL and UApp to corrupt sensitive memory locationspotentially resulting in a loss of integrity or availability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24943 ‼

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20098 ‼

A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this vulnerability by running a system command containing directory traversal character sequences to target an arbitrary file. A successful exploit could allow the attacker to delete arbitrary files from the system, including files owned by root.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24903 ‼

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24939 ‼

Server for NFS Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24899 ‼

Windows Graphics Component Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24932 ‼

Secure Boot Security Feature Bypass Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-29336 ‼

Win32k Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-29340 ‼

AV1 Video Extension Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".