πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-43890 β€Ό

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43268 β€Ό

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44008 β€Ό

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3592 β€Ό

In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43297 β€Ό

An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5344 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44011 β€Ό

An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31042 β€Ό

A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBladeÒ€ℒs object store protocol can impact the availability of the systemÒ€ℒs data access and replication protocols.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43980 β€Ό

Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43891 β€Ό

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36627 β€Ό

A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43893 β€Ό

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28372 β€Ό

A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an objectÒ€ℒs retention period can affect the availability of the object lock.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44012 β€Ό

Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43892 β€Ό

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43627 β€Ό

Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent authenticated attacker to alter critical information such as system files by sending a specially crafted request. They are affected when running in ST(Standalone) mode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5334 β€Ό

The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsiveslider' shortcode in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5345 β€Ό

A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation.In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free.We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32572 β€Ό

A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41086 β€Ό

Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.

πŸ“– Read

via "National Vulnerability Database".