πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-5175 β€Ό

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-41067 β€Ό

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may bypass Gatekeeper checks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43857 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /admin/u/toIndex.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41981 β€Ό

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44122 β€Ό

The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. They also can return arbitrary data that will be passed to the "onActivityResult()" method. The LockScreenSettings app copies the received file to the "/data/shared/dw/mycategory/wallpaper_01.png" path and then changes the file access mode to world-readable and world-writable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41335 β€Ό

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilitiesÒ€”it already learns the users' passwords as part of the authentication processÒ€”it does disrupt the expectation that passwords won't be stored in the database. As a result, these passwords could inadvertently be captured in database backups for a longer duration. These temporarily stored passwords are automatically erased after a 48-hour window. This issue has been addressed in version 1.93.0. Users are advised to upgrade. There are no known workarounds for this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41070 β€Ό

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive data logged when a user shares a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43775 β€Ό

Denial-of-service vulnerability in the web server of the Eaton SMP SG-4260 allows attacker to potentially force an unexpected restart of the SMP Gatewayautomation platform, impacting the availability of the product. In rare situations, the issue could causethe SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product isnot vulnerable anymore.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44127 β€Ό

he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact details and phone numbers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5157 β€Ό

A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44016 β€Ό

Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43614 β€Ό

Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28490 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <=Γ‚ 2.0.7 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44124 β€Ό

The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. They also can return arbitrary data that will be passed to the "onActivityResult()" method. The Screen recording app saves contents of arbitrary URIs to SD card which is a world-readable storage.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41962 β€Ό

Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44128 β€Ό

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40676 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <=Γ‚ 5.0.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43646 β€Ό

get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: '\t'.repeat(54773) + '\t/function/i'. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40663 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rextheme WP VR plugin <=Γ‚ 8.3.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41306 β€Ό

Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43232 β€Ό

A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.

πŸ“– Read

via "National Vulnerability Database".