πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-32758 β€Ό

giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep through 1.21.0, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22318 β€Ό

Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32784 β€Ό

In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character cannot be recovered. In 2.54, there is different API usage and/or random string insertion for mitigation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1698 β€Ό

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ VMware’s ESXi security issues spur new ransomware gang into action πŸ“’

The popularity of ESXi combined with a lack of security tools makes it an β€œattractive target” for threat actors

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-23449 β€Ό

Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attackerto gain information about valid usernames by analyzing challenge responses from the server via theREST interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47387 β€Ό

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23447 β€Ό

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivilegedremote attacker to influence the availability of the webserver by invocing several open file requests viathe REST interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47378 β€Ό

Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22508 β€Ό

Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23448 β€Ό

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows aremote attacker to gain information about valid usernames via analysis of source code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31409 β€Ό

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22684 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Subscribers.Com Subscribers plugin <=Γ‚ 1.5.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47390 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47393 β€Ό

An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23445 β€Ό

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remoteattacker to gain unauthorized access to data fields by using a therefore unpriviledged account via theREST interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47388 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47385 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47381 β€Ό

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31408 β€Ό

Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR withPartnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remoteattacker to potentially steal user credentials that are stored in the userÒ€ℒs browsers local storage viacross-site-scripting attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47391 β€Ό

In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.

πŸ“– Read

via "National Vulnerability Database".