πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-2060

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1855

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-0837

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-9356

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-3591

Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7484

Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4410

ReviewBoard: has an access-control problem in REST API

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-5562

rhn-proxy: may transmit credentials over clear-text when accessing RHN Satellite

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4576

FreeBSD: Input Validation Flaw allows local users to gain elevated privileges

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4526

piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4525

piwigo has XSS in password.php

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Leveraging the Cloud for Cyber Intelligence πŸ•΄

How fusing output datasets and sharing information can create a real-time understanding of suspicious activity across your enterprise.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-2228

SaltStack RSA Key Generation allows remote users to decrypt communications

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2106

webauth before 4.6.1 has authentication credential disclosure

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2103

OpenShift cartridge allows remote URL retrieval

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2101

Katello has multiple XSS issues in various entities

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4525

piwigo has XSS in password.php

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4480

mom creates world-writable pid files in /var/run

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4428

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Siemens Offers Workarounds for Newly Found PLC Vulnerability πŸ•΄

An undocumented hardware-based special access feature recently found by researchers in Siemens' S7-1200 can be used by attackers to gain control of the industrial devices.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Android Flaw Leads to β€˜Permanent DoS’ ❌

The December security update stomped out critical denial-of-service (DoS) and remote-code-execution (RCE) vulnerabilities in the Android operating system.

πŸ“– Read

via "Threatpost".