🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2023-24941 ‼

Windows Network File System Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24900 ‼

Windows NTLM Security Support Provider Information Disclosure Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24950 ‼

Microsoft SharePoint Server Spoofing Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-26354 ‼

Insufficient bounds checking in ASP may allow anattacker to issue a system call from a compromised ABL which may causearbitrary memory values to be initialized to zero, potentially leading to aloss of integrity.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20520 ‼

Improper access control settings in ASPBootloader may allow an attacker to corrupt the return address causing astack-based buffer overrun potentially leading to arbitrary code execution.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-46763 ‼

Insufficient input validation in the SMU mayenable a privileged attacker to write beyond the intended bounds of a sharedmemory buffer potentially leading to a loss of integrity.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20524 ‼

An attacker with a compromised ASP couldpossibly send malformed commands to an ASP on another CPU, resulting in an outof bounds write, potentially leading to a loss a loss of integrity.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-26356 ‼

A TOCTOU in ASP bootloader may allow an attackerto tamper with the SPI ROM following data read to memory potentially resultingin S3 data corruption and information disclosure.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-26397 ‼

Insufficient address validation, may allow anattacker with a compromised ABL and UApp to corrupt sensitive memory locationspotentially resulting in a loss of integrity or availability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24943 ‼

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20098 ‼

A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this vulnerability by running a system command containing directory traversal character sequences to target an arbitrary file. A successful exploit could allow the attacker to delete arbitrary files from the system, including files owned by root.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24903 ‼

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24939 ‼

Server for NFS Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24899 ‼

Windows Graphics Component Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24932 ‼

Secure Boot Security Feature Bypass Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-29336 ‼

Win32k Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-29340 ‼

AV1 Video Extension Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-31472 ‼

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-28283 ‼

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24954 ‼

Microsoft SharePoint Server Information Disclosure Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-24955 ‼

Microsoft SharePoint Server Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".