🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2023-20811 ‼

In IOMMU, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID: DTV03692061.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20810 ‼

In IOMMU, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID: DTV03692061.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33910 ‼

In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20813 ‼

In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453549; Issue ID: ALPS07453549.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20797 ‼

In camera middleware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629582; Issue ID: ALPS07629582.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20798 ‼

In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147572; Issue ID: ALPS07421076.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-33908 ‼

In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20807 ‼

In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608433; Issue ID: ALPS07608433.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20818 ‼

In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460540; Issue ID: ALPS07460540.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20808 ‼

In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID: DTV03645895.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20785 ‼

In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628524; Issue ID: ALPS07628524.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20801 ‼

In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420968.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20786 ‼

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ALPS07767811.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20805 ‼

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326411.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-47350 ‼

In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20800 ‼

In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420955.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-20790 ‼

In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID: ALPS07740194.

📖 Read

via "National Vulnerability Database".
🕴 The Dark Web Is Expanding (As Is the Value of Monitoring It) 🕴

Rising cybercrime threats heighten risks. Dark Web monitoring offers early alerts and helps lessen exposures.

📖 Read

via "Dark Reading".
🦿 How an 8-character password could be cracked in just a few minutes 🦿

Advances in graphics processing technology and AI have slashed the time needed to crack a password using brute force techniques, says Hive Systems.

📖 Read

via "Tech Republic".
🕴 Name That Edge Toon: How Now? 🕴

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

📖 Read

via "Dark Reading".
‼ CVE-2023-38392 ‼

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.9 versions.

📖 Read

via "National Vulnerability Database".