πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-29328 β€Ό

Microsoft Teams Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35388 β€Ό

Microsoft Exchange Server Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35371 β€Ό

Microsoft Office Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36532 β€Ό

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38176 β€Ό

Azure Arc-Enabled Servers Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
🦿 Microsoft Azure AI Adds GPT-4 and New Virtual Machines 🦿

Microsoft is working on creating guidelines for red teams making sure generative AI is secure and responsible.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2023-26961 β€Ό

Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files by changing the extension of the uploaded file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39086 β€Ό

ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36344 β€Ό

An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36482 β€Ό

An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking its input size can cause an NFC service restart.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Microsoft Patch Tuesday, August 2023 Edition β™ŸοΈ

Microsoft Corp. today issued software updates to plug more than 70 security holes in its Windows operating systems and related products, including a patch that addresses multiple zero-day vulnerabilities currently being exploited in the wild.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2023-3632 β€Ό

Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass.This issue affects Kunduz - Homework Helper App: before 6.2.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37855 β€Ό

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24477 β€Ό

In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22378 β€Ό

A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37856 β€Ό

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22843 β€Ό

An authenticated attacker with administrative access to the appliance can inject malicious JavaScript code inside the definition of a Threat Intelligence rule, that will later be executed by another legitimate user viewing the details of such a rule.An attacker may be able to perform unauthorized actions on behalf of legitimate users. JavaScript injection was possible in the content for Yara rules, while limited HTML injection has been proven for packet and STYX rules.The injected code will be executed in the context of the authenticated victim's session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2905 β€Ό

Due to a failure in validating the length of a provided MQTT_CMD_PUBLISHΓ‚ parsed message with a variable length header, Cesanta Mongoose, anΓ‚ embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23574 β€Ό

A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47185 β€Ό

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37857 β€Ό

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. This issue cannot be exploited to bypass the web service authentication of the affected device(s).

πŸ“– Read

via "National Vulnerability Database".