โผ CVE-2023-42443 โผ
๐ Read
via "National Vulnerability Database".
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under certain conditions, the memory used by the builtins `raw_call`, `create_from_blueprint` and `create_copy_of` can be corrupted. For `raw_call`, the argument buffer of the call can be corrupted, leading to incorrect `calldata` in the sub-context. For `create_from_blueprint` and `create_copy_of`, the buffer for the to-be-deployed bytecode can be corrupted, leading to deploying incorrect bytecode.Each builtin has conditions that must be fulfilled for the corruption to happen. For `raw_call`, the `data` argument of the builtin must be `msg.data` and the `value` or `gas` passed to the builtin must be some complex expression that results in writing to the memory. For `create_copy_of`, the `value` or `salt` passed to the builtin must be some complex expression that results in writing to the memory. For `create_from_blueprint`, either no constructor parameters should be passed to the builtin or `raw_args` should be set to True, and the `value` or `salt` passed to the builtin must be some complex expression that results in writing to the memory.As of time of publication, no patched version exists. The issue is still being investigated, and there might be other cases where the corruption might happen. When the builtin is being called from an `internal` function `F`, the issue is not present provided that the function calling `F` wrote to memory before calling `F`. As a workaround, the complex expressions that are being passed as kwargs to the builtin should be cached in memory prior to the call to the builtin.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-39040 โผ
๐ Read
via "National Vulnerability Database".
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-39058 โผ
๐ Read
via "National Vulnerability Database".
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-39446 โผ
๐ Read
via "National Vulnerability Database".
** UNSUPPPORTED WHEN ASSIGNED ** Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-39452 โผ
๐ Read
via "National Vulnerability Database".
** UNSUPPPORTED WHEN ASSIGNED ** The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.๐ Read
via "National Vulnerability Database".
๐1
๐ฆฟ White Hat Hackers Discover Microsoft Leak of 38TB of Internal Data Via Azure Storage ๐ฆฟ
๐ Read
via "Tech Republic".
The Microsoft leak, which stemmed from AI researchers sharing open-source training data on GitHub, has been mitigated.๐ Read
via "Tech Republic".
TechRepublic
White Hat Hackers Discover Microsoft Leak of 38TB of Internal Data Via Azure Storage
The Microsoft leak, which stemmed from AI researchers sharing open-source training data on GitHub, has been mitigated.
๐ด Niagara Networks and Scope Middle East Announce Strategic VAD Partnership ๐ด
๐ Read
via "Dark Reading".
๐ Read
via "Dark Reading".
Dark Reading
Niagara Networks and Scope Middle East Announce Strategic VAD Partnership
FREMONT, Calif., Sept. 18, 2023 /PRNewswire/ -- Niagara Networksโข, a Silicon Valley-based company that pioneers the award-winning Open Visibility Platformโข, announced today a new partnership with SCOPE Middle Eastยฎ, a Value-Added Distribution leader in theโฆ
โผ CVE-2023-42454 โผ
๐ Read
via "National Vulnerability Database".
SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable), with the web_root is the current working directory (the default), and with their database exposed publicly, is vulnerable to an attacker retrieving database connection information from SQLPage and using it to connect to their database directly. Version 0.11.0 fixes this issue. Some workarounds are available. Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. Using a different web root (that is not a parent of the SQLPage configuration directory) fixes the issue. One should also avoid exposing one's database publicly.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-37611 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-39056 โผ
๐ Read
via "National Vulnerability Database".
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-41443 โผ
๐ Read
via "National Vulnerability Database".
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-42446 โผ
๐ Read
via "National Vulnerability Database".
Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than a session's remaining TTL. Version 1.0.34 contains a patch for this issue. As a workaround, expired keys, including all expired sessions, can be manually invalidated.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-39049 โผ
๐ Read
via "National Vulnerability Database".
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.๐ Read
via "National Vulnerability Database".
๐1
โผ CVE-2023-39046 โผ
๐ Read
via "National Vulnerability Database".
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-41599 โผ
๐ Read
via "National Vulnerability Database".
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-40788 โผ
๐ Read
via "National Vulnerability Database".
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs๐ Read
via "National Vulnerability Database".
โผ CVE-2023-5060 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-28357 โผ
๐ Read
via "National Vulnerability Database".
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-42399 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-26837 โผ
๐ Read
via "National Vulnerability Database".
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.๐ Read
via "National Vulnerability Database".
๐ด 'ShroudedSnooper' Backdoors Use Ultra-Stealth in Mideast Telecom Attacks ๐ด
๐ Read
via "Dark Reading".
The threat cluster hasn't been seen before, but its custom Windows server backdoors have researchers intrigued thanks to their extremely effective stealth mechanisms.๐ Read
via "Dark Reading".
Dark Reading
'ShroudedSnooper' Backdoors Use Ultra-Stealth in Mideast Telecom Attacks
The threat cluster hasn't been seen before, but its custom Windows server backdoors have researchers intrigued thanks to their extremely effective stealth mechanisms.
๐1