πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-40896 β€Ό

A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30799 β€Ό

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33876 β€Ό

A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. A specially-crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object which can lead to memory corruption and result in arbitrary code execution. A specially-crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32664 β€Ό

A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. A specially-crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a malicious file to trigger the vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33866 β€Ό

A use-after-free vulnerability exists in the JavaScript engine of Foxit SoftwareÒ€ℒs PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated with pages, a specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28744 β€Ό

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.1.1.15289. A specially crafted PDF document can trigger the reuse of previously freed memory by manipulating form fields of a specific type. This can lead to memory corruption and arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34034 β€Ό

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3638 β€Ό

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27379 β€Ό

A use-after-free vulnerability exists in the JavaScript engine of Foxit SoftwareÒ€ℒs PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated with pages, a specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3463 β€Ό

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3467 β€Ό

Privilege Escalation to root administrator (nsroot)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3519 β€Ό

Unauthenticated remote code execution

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3466 β€Ό

Reflected Cross-Site Scripting (XSS)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37733 β€Ό

An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3674 β€Ό

A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.

πŸ“– Read

via "National Vulnerability Database".
🦿 5 Deepfake Scams That Threaten Enterprises 🦿

Forrester shines a light on the synthetic attacks that can cause organizations considerable headaches.

πŸ“– Read

via "Tech Republic".
πŸ‘1
🦿 Forrester’s Top 10 Emerging Technologies in 2023 and Beyond 🦿

The research firm outlines when the average organization should expect a technology to deliver the benefits necessary to justify continued investment.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2023-34429 β€Ό

Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35134 β€Ό

Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding accountÒ€ℒs JWT token only.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36853 β€Ό

?In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37362 β€Ό

Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.

πŸ“– Read

via "National Vulnerability Database".