🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼️CVE-2023-32883‼️

In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID ALPS08282249 Issue ID ALPS08282249.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32884‼️

In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID ALPS07944011 Issue ID ALPS07944011.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32885‼️

In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID ALPS07780685 Issue ID ALPS07780685.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32886‼️

In Modem IMS SMS UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID MOLY00730807 Issue ID MOLY00730807.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32887‼️

In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID MOLY01161837 Issue ID MOLY01161837 MSV892.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32888‼️

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID MOLY01161830 Issue ID MOLY01161830 MSV894.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32889‼️

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID MOLY01161825 Issue ID MOLY01161825 MSV895.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32890‼️

In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID MOLY01183647 Issue ID MOLY01183647 MSV963.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-32891‼️

In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID ALPS07933038 Issue ID MSV559.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-26157‼️

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service DoS due to an outofbounds read involving sectionnumpages in decoder2007.c.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-26159‼️

Versions of the package followredirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse function. When new URL throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-28583‼️

Memory corruption when IPv6 prefix timer objects lifetime expires which are created while Netmgr daemon gets an IPv6 address.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33014‼️

Information disclosure in Core services while processing a Diag command.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33025‼️

Memory corruption in Data Modem when a nonstandard SDP body, during a VOLTE call.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33030‼️

Memory corruption in HLOS while running playready usecase.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33032‼️

Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33033‼️

Memory corruption in Audio during playback with speaker protection.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33036‼️

Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33037‼️

Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33038‼️

Memory corruption while receiving a message in Bus Socket Transport Server.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33040‼️

Transient DOS in Data Modem during DTLS handshake.

📖 Read more

Via "National Vulnerability Database"