🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2023-4342 ‼

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4355 ‼

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-38861 ‼

An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4333 ‼

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4332 ‼

Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4352 ‼

Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4330 ‼

Broadcom RAID Controller web interface is vulnerable Denial of Service can be caused by an authenticated user to the REST API Interface

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4351 ‼

Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4336 ‼

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4338 ‼

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4324 ‼

Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4329 ‼

Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4339 ‼

Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4353 ‼

Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4325 ‼

Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4341 ‼

Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4326 ‼

Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4369 ‼

Insufficient data validation in Systems Extensions in Google Chrome on ChromeOS prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass file restrictions via a crafted HTML page. (Chromium security severity: Medium)

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4364 ‼

Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4363 ‼

Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4366 ‼

Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

📖 Read

via "National Vulnerability Database".