πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-4057 β€Ό

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116 and Firefox ESR < 115.1.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-33493 β€Ό

An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4056 β€Ό

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36210 β€Ό

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38559 β€Ό

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4054 β€Ό

When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36211 β€Ό

The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38560 β€Ό

An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Space Pirates Train Cyber Sabers on Russian, Serbian Organizations πŸ•΄

The attackers have expanded beyond backdoors and recently started using Deed RAT to step up their attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Canon Inkjet Printers at Risk for Third-Party Compromise via Wi-Fi πŸ•΄

Nearly 200 models are affected by vulnerability that may give wireless access to unauthorized third parties.

πŸ“– Read

via "Dark Reading".
πŸ•΄ White House Cyber Workforce Strategy: No Quick Fix for Skills Shortage πŸ•΄

A lot of what the strategy proposes is well-intentioned but somewhat aspirational at the moment, industry experts say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-31429 β€Ό

Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability when using various commands such as Ò€œchassisdistributeҀ�, Ò€œrebootҀ�, Ò€œrasmanҀ�, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands that can cause the content of shell interpreted variables to be printed in the terminal.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31425 β€Ό

A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, Ò€œrootҀ� account access is disabled.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3500 β€Ό

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3900 β€Ό

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-3994 β€Ό

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1210 β€Ό

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict membership by email domain.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31428 β€Ό

Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep.

πŸ“– Read

via "National Vulnerability Database".