‼ CVE-2023-36327 ‼
📖 Read
via "National Vulnerability Database".
Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-36088 ‼
📖 Read
via "National Vulnerability Database".
Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-36100 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-36326 ‼
📖 Read
via "National Vulnerability Database".
Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40968 ‼
📖 Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in hzeller timg v.1.5.2 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40980 ‼
📖 Read
via "National Vulnerability Database".
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-39582 ‼
📖 Read
via "National Vulnerability Database".
SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-39631 ‼
📖 Read
via "National Vulnerability Database".
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-41628 ‼
📖 Read
via "National Vulnerability Database".
An issue in O-RAN Software Community E2 G-Release allows attackers to cause a Denial of Service (DoS) by incorrectly initiating the messaging procedure between the E2Node and E2Term components.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-3407 ‼
📖 Read
via "National Vulnerability Database".
I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This patch resolves the device's modem reset issue.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4721 ‼
📖 Read
via "National Vulnerability Database".
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40771 ‼
📖 Read
via "National Vulnerability Database".
SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4722 ‼
📖 Read
via "National Vulnerability Database".
Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-22612 ‼
📖 Read
via "National Vulnerability Database".
Installer RCE on settings file write in MyBB before 1.8.22.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-41627 ‼
📖 Read
via "National Vulnerability Database".
O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.📖 Read
via "National Vulnerability Database".
🦿 UK’s NCSC Warns Against Cybersecurity Attacks on AI 🦿
📖 Read
via "Tech Republic".
The National Cyber Security Centre provides details on prompt injection and data poisoning attacks so organizations using machine-learning models can mitigate the risks.📖 Read
via "Tech Republic".
TechRepublic
UK’s NCSC Warns Against Cybersecurity Attacks on AI
U.K.’s National Cyber Security Centre publication on AI details attacks that might target organizations implementing or developing ML models.
🕴 MSSQL Databases Under Fire From FreeWorld Ransomware 🕴
📖 Read
via "Dark Reading".
The sophisticated attacks, tracked as DB#JAMMER, run shell commands to impair defenses and deploy tools to establish persistence on the host.📖 Read
via "Dark Reading".
Dark Reading
MSSQL Databases Under Fire From FreeWorld Ransomware
The sophisticated attacks, tracked as DB#JAMMER, run shell commands to impair defenses and deploy tools to establish persistence on the host.
🕴 US Government Denies Blocking Sales of AI Chips to Middle East 🕴
📖 Read
via "Dark Reading".
Nvidia and AMD do face expanded export rules for their A100 and H100 artificial intelligence (AI) chips in the Middle East, but it's not yet clear why.📖 Read
via "Dark Reading".
Dark Reading
US Government Denies Blocking Sales of AI Chips to Middle East
Nvidia and AMD do face expanded export rules for their A100 and H100 artificial intelligence (AI) chips in the Middle East, but it's not yet clear why.
🕴 Inaugural Pwn2Own Automotive Contest Dangles $1M for Car Hackers 🕴
📖 Read
via "Dark Reading".
The competition encourages automotive research and allows for contestants to take part in person or remotely.📖 Read
via "Dark Reading".
Dark Reading
Inaugural Pwn2Own Automotive Contest Dangles $1M for Car Hackers
The competition encourages automotive research and allows for contestants to take part in person or remotely.
‼ CVE-2023-4709 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file Login.aspx of the component Portal. The manipulation of the argument VIEWSTATE leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-238572. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-41633 ‼
📖 Read
via "National Vulnerability Database".
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.📖 Read
via "National Vulnerability Database".