βΌ CVE-2023-30356 βΌ
π Read
via "National Vulnerability Database".
Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmwareπ Read
via "National Vulnerability Database".
βΌ CVE-2023-30351 βΌ
π Read
via "National Vulnerability Database".
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31567 βΌ
π Read
via "National Vulnerability Database".
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30352 βΌ
π Read
via "National Vulnerability Database".
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.π Read
via "National Vulnerability Database".
β€1
βΌ CVE-2023-31555 βΌ
π Read
via "National Vulnerability Database".
podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31566 βΌ
π Read
via "National Vulnerability Database".
Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().π Read
via "National Vulnerability Database".
βΌ CVE-2023-31557 βΌ
π Read
via "National Vulnerability Database".
xpdf pdfimages v4.04 was discovered to contain a stack overflow in the component Catalog::readEmbeddedFileTree(Object*). This vulnerability allows attackers to cause a Denial of Service (DoS).π Read
via "National Vulnerability Database".
βΌ CVE-2023-2630 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31556 βΌ
π Read
via "National Vulnerability Database".
podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent.π Read
via "National Vulnerability Database".
βΌ CVE-2022-46378 βΌ
π Read
via "National Vulnerability Database".
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no port argument is provided to the `PORT` command.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30354 βΌ
π Read
via "National Vulnerability Database".
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30353 βΌ
π Read
via "National Vulnerability Database".
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0007 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administratorΓ’β¬β’s browser when viewed.π Read
via "National Vulnerability Database".
βΌ CVE-2023-2629 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31568 βΌ
π Read
via "National Vulnerability Database".
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31554 βΌ
π Read
via "National Vulnerability Database".
xpdf pdfimages v4.04 was discovered to contain a stack overflow in the component Catalog::readPageLabelTree2(Object*). This vulnerability allows attackers to cause a Denial of Service (DoS).π Read
via "National Vulnerability Database".
βΌ CVE-2022-41985 βΌ
π Read
via "National Vulnerability Database".
An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-0008 βΌ
π Read
via "National Vulnerability Database".
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with access to the web interface to export local files from the firewall through a race condition.π Read
via "National Vulnerability Database".
π΄ Sysco Data Breach Exposes Customer, Employee Data π΄
π Read
via "Dark Reading".
Food distribution company first learned of the cyberattack in March 2023.π Read
via "Dark Reading".
Dark Reading
Sysco Data Breach Exposes Customer, Employee Data
Food distribution company first learned of the cyberattack in March 2023.
π΄ Dark Reading Goes Global π΄
π Read
via "Dark Reading".
While the goal of the site's new DR Global section is to expand international coverage, the initial focus will be cybersecurity professionals in the Middle East and Africa.π Read
via "Dark Reading".
Dark Reading
Dark Reading Goes Global
While the goal of the site's new DR Global section is to expand international coverage, the initial focus will be cybersecurity professionals in the Middle East and Africa.
π΄ Microsoft Fixes Failed Patch for Exploited Outlook Vulnerability π΄
π Read
via "Dark Reading".
Adding a single character to a function in the previous Outlook patch rendered that fix useless, researchers say.π Read
via "Dark Reading".
Dark Reading
Microsoft Fixes Failed Patch for Exploited Outlook Vulnerability
Adding a single character to a function in the previous Outlook patch rendered that fix useless, researchers say.