🛡 Cybersecurity & Privacy 🛡 - News
26.2K subscribers
89.3K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼️CVE-2023-33112‼️

Transient DOS when WLAN firmware receives "reassoc response" frame including RICDATA element.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33113‼️

Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33114‼️

Memory corruption while running NPU, when NETWORKUNLOAD and NETWORKUNLOAD or NETWORKEXECUTEV2 commands are submitted at the same time.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33116‼️

Transient DOS while parsing ieee80211parsemscsie in WIN WLAN driver.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33117‼️

Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCSLOADMODULE command.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33118‼️

Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-33120‼️

Memory corruption in Audio when memory map command is executed consecutively in ADSP.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-43511‼️

Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-43512‼️

Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-43514‼️

Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-47039‼️

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell cmd.exe. When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute cmd.exe within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to placecmd.exe in locations with weak permissions, such as CProgramData. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-47216‼️

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-47857‼️

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-48360‼️

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-49135‼️

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-49142‼️

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-47858‼️

Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET apiv4teamschannelsdeleted endpoint.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-48732‼️

Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50333‼️

Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-6693‼️

A stack based buffer overflow was found in the virtionet device of QEMU. This issue occurs when flushing TX in the virtionetflushtx function if guest features VIRTIONETFHASHREPORT, VIRTIOFVERSION1 and VIRTIONETFMRGRXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the outsg variable could be used to read a part of process memory and send it to the wire, causing an information leak.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-6436‼️

Improper Neutralization of Special Elements used in an SQL Command 'SQL Injection' vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template through 20231215.

📖 Read more

Via "National Vulnerability Database"