🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Key Group Ransomware Foiled by New Decryptor 🕴

Researchers crack Key Group's ransomware encryption and release free tool for victim organizations to recover their data.

📖 Read

via "Dark Reading".
‼ CVE-2023-36076 ‼

SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-36187 ‼

Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-36328 ‼

Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-28366 ‼

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4720 ‼

Floating Point Comparison with Incorrect Operator in GitHub repository gpac/gpac prior to 2.3-DEV.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-36327 ‼

Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-36088 ‼

Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-36100 ‼

An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-36326 ‼

Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-40968 ‼

Buffer Overflow vulnerability in hzeller timg v.1.5.2 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-40980 ‼

File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-39582 ‼

SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-39631 ‼

An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-41628 ‼

An issue in O-RAN Software Community E2 G-Release allows attackers to cause a Denial of Service (DoS) by incorrectly initiating the messaging procedure between the E2Node and E2Term components.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-3407 ‼

I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This patch resolves the device's modem reset issue.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4721 ‼

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-40771 ‼

SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-4722 ‼

Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.

📖 Read

via "National Vulnerability Database".
‼ CVE-2020-22612 ‼

Installer RCE on settings file write in MyBB before 1.8.22.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-41627 ‼

O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.

📖 Read

via "National Vulnerability Database".