๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-27854 โ€ผ

An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow. ร‚ The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product. ร‚ The user would need to open a malicious file provided to them by the attacker for the code to execute.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46289 โ€ผ

Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34886 โ€ผ

A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34887 โ€ผ

Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3429 โ€ผ

A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-4967 โ€ผ

Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-27858 โ€ผ

Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using anร‚ uninitialized pointer in the application. ร‚ The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product. ร‚ The user would need to open a malicious file provided to them by the attacker for the code to execute.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46290 โ€ผ

Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalkร‚ยฎ Services Platform web service and then use the token to log in into FactoryTalkร‚ยฎ Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalkร‚ยฎ Services Platform web service.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Safari Side-Channel Attack Enables Browser Theft ๐Ÿ•ด

The "iLeakage" attack affects all recent iPhone, iPad, and MacBook models, allowing attackers to peruse your Gmail inbox, steal your Instagram password, or scrutinize your YouTube history.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘1
โ€ผ CVE-2023-40139 โ€ผ

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
โ€ผ CVE-2023-40136 โ€ผ

In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40121 โ€ผ

In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40125 โ€ผ

In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40123 โ€ผ

In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40116 โ€ผ

In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40128 โ€ผ

In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46509 โ€ผ

An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46208 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors รขโ‚ฌโ€œ Car Dealer, Classifieds & Listing plugin <=ร‚ 1.4.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5828 โ€ผ

A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243727.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34834 โ€ผ

An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40127 โ€ผ

In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".