πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-24847 β€Ό

Transient DOS in Modem while allocating DSM items.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24853 β€Ό

Memory Corruption in HLOS while registering for key provisioning notify.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3655 β€Ό

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a dangerous methods, that allows to leak the database (system settings, user accounts,...).Γ‚ This vulnerability can be triggered by an HTTP endpoint exposed to the network.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24844 β€Ό

Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21673 β€Ό

Improper Access to the VM resource manager can lead to Memory Corruption.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24849 β€Ό

Information Disclosure in data Modem while parsing an FMTP line in an SDP message.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33039 β€Ό

Memory corruption in Automotive Display while destroying the image handle created using connected display driver.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28540 β€Ό

Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44218 β€Ό

A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33029 β€Ό

Memory corruption in DSP Service during a remote call from HLOS to DSP.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24855 β€Ό

Memory corruption in Modem while processing security related configuration before AS Security Exchange.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22382 β€Ό

Weak configuration in Automotive while VM is processing a listener request from TEE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28571 β€Ό

Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ransomware Crisis, Recession Fears Leave CISOs in Tough Spot πŸ•΄

Combining robust decryption and orchestration of encrypted traffic with threat prevention is crucial to staying ahead of attackers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Name That Edge Toon: Office Artifacts πŸ•΄

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-47892 β€Ό

All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47893 β€Ό

There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25989 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading toΓ‚ dismiss or the popup.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42508 β€Ό

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5351 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39923 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <=Γ‚ 7.2.7 versions.

πŸ“– Read

via "National Vulnerability Database".