🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2023-35321 ‼

Windows Deployment Services Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35298 ‼

HTTP.sys Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35300 ‼

Remote Procedure Call Runtime Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35362 ‼

Windows Clip Service Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-32054 ‼

Volume Shadow Copy Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35314 ‼

Remote Procedure Call Runtime Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35339 ‼

Windows CryptoAPI Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35309 ‼

Microsoft Message Queuing Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35335 ‼

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35317 ‼

Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33174 ‼

Windows Cryptographic Information Disclosure Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35305 ‼

Windows Kernel Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-32047 ‼

Paint 3D Remote Code Execution Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-35316 ‼

Remote Procedure Call Runtime Information Disclosure Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33169 ‼

Remote Procedure Call Runtime Denial of Service Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33155 ‼

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-32040 ‼

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-23756 ‼

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-29984 ‼

Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-48521 ‼

An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2. It fails to keep track of ordinal numbers when removing fake Authentication-Results header fields, which allows a remote attacker to craft an e-mail message with a fake sender address such that programs that rely on Authentication-Results from OpenDKIM will treat the message as having a valid DKIM signature when in fact it has none.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-29406 ‼

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

📖 Read

via "National Vulnerability Database".