πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-21118 β€Ό

In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21104 β€Ό

In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-259938771

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20707 β€Ό

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628556; Issue ID: ALPS07628556.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20704 β€Ό

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2708 β€Ό

The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Γ’β‚¬Λœsearch_termÒ€ℒ parameter in versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2710 β€Ό

The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-29961 β€Ό

D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23709 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Denis WPJAM Basic plugin <=Γ‚ 6.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23703 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <=Γ‚ 2.1.7 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23657 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Richard Leishman t/a Webforward Mail Subscribe List plugin <=Γ‚ 2.1.9 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23720 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin <=Γ‚ 2.3.13 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23641 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPmanage Uji Popup plugin <=Γ‚ 1.4.3 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Is the new .zip top-level domain a cyber security risk? πŸ“’

While some experts have branded the new domain β€˜unnecessary’, others dispute its usefulness for attacks

πŸ“– Read

via "ITPro".
β™ŸοΈ Re-Victimization from Police-Auctioned Cell Phones β™ŸοΈ

Countless smartphones seized in arrests and searches by police forces across the United States are being auctioned online without first having the data on them erased, a practice that can lead to crime victims being re-victimized, a new study found. In response, the largest online marketplace for items seized in U.S. law enforcement investigations says it now ensures that all phones sold through its platform will be data-wiped prior to auction.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ 4 Big Mistakes to Avoid in OT Incident Response πŸ•΄

What works in IT may not in an operational technology/industrial control systems environment where availability and safety of operations must be maintained.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2730 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Severe RCE Bugs Open Thousands of Industrial IoT Devices to Cyberattack πŸ•΄

Researchers found 11 vulnerabilities in products from three industrial cellular router vendors that attackers can exploit through various vectors, bypassing all security layers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-31857 β€Ό

Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29439 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <=Γ‚ 2.2.35 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2738 β€Ό

A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-229149 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31587 β€Ό

Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

πŸ“– Read

via "National Vulnerability Database".