π¨ CVE-2019-16258
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.
π@cveNotify
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.
π@cveNotify
homee
homee Brain Cube
Produktdetails
Basis fΓΌr dein intelligentes Zuhause
Verbindet viele GerΓ€te von Netatmio Homematic, AVM FRITZ, Nuki
Speichert alle Daten verschlΓΌsselt und lo...
Basis fΓΌr dein intelligentes Zuhause
Verbindet viele GerΓ€te von Netatmio Homematic, AVM FRITZ, Nuki
Speichert alle Daten verschlΓΌsselt und lo...
π¨ CVE-2019-19148
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH.
π@cveNotify
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH.
π@cveNotify
GitHub
GitHub - ellwoodthewood/tellabs_rce: Tellabs OLT RCE
Tellabs OLT RCE. Contribute to ellwoodthewood/tellabs_rce development by creating an account on GitHub.
π¨ CVE-2019-19324
Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted accidental JWT acceptance.
π@cveNotify
Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted accidental JWT acceptance.
π@cveNotify
GitHub
Merge pull request #29 from xmidt-org/correct-return-codes-and-elimin⦠· xmidt-org/cjwt@9304d3e
β¦iate-silent-failure
Correct return codes and eliminiate silent failure
Correct return codes and eliminiate silent failure
π¨ CVE-2020-10792
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
π@cveNotify
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
π@cveNotify
GitHub
Debug Mode can now only be enabled by an environment variable Β· it-novum/openITCOCKPIT@719410b
openITCOCKPIT is an Open Source system monitoring tool built for different monitoring engines like Nagios or Naemon. - it-novum/openITCOCKPIT
π¨ CVE-2020-9425
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.
π@cveNotify
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.
π@cveNotify
Medium
Advisory: rConfig 3.9.3 Unauthenticated Sensitive Information Disclosure
Affected Vendor: rConfig Affected Software: rConfig Affected Version: Tested on version 3.9.3, possibly affecting earlier versions Issueβ¦
π¨ CVE-2019-12498
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
π@cveNotify
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
π@cveNotify
π¨ CVE-2019-13389
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
π@cveNotify
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
π@cveNotify
GitHub
Improved app security Β· RainLoop/rainloop-webmail@8eb4588
Simple, modern & fast web-based email client. Contribute to RainLoop/rainloop-webmail development by creating an account on GitHub.
π¨ CVE-2020-10558
The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other miscellaneous functions from the main screen.
π@cveNotify
The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other miscellaneous functions from the main screen.
π@cveNotify
π¨ CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
π@cveNotify
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
π@cveNotify
π¨ CVE-2019-13463
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html is not called for the "echo get_the_title()" or "echo $term->name" statement.
π@cveNotify
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html is not called for the "echo get_the_title()" or "echo $term->name" statement.
π@cveNotify
π¨ CVE-2019-15522
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
π@cveNotify
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
π@cveNotify
GitHub
some security improvements by maltek Β· Pull Request #13 Β· LINBIT/csync2
Following up to a private email conversation with @lge.
π¨ CVE-2019-16528
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and summaries, from AbuseLog revision data. This affects REL1_32 and REL1_33.
π@cveNotify
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and summaries, from AbuseLog revision data. This affects REL1_32 and REL1_33.
π@cveNotify
π¨ CVE-2019-18641
Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.
π@cveNotify
Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.
π@cveNotify
GitHub
+ Changed vCard to be secured by adjustments to the People/GetVCard/ β¦ Β· SparkDevNetwork/Rock@576f5ec
β¦REST controller.
π¨ CVE-2019-18860
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
π@cveNotify
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
π@cveNotify
GitHub
cachemgr.cgi: Add validation for hostname parameter by aaron-costello Β· Pull Request #504 Β· squid-cache/squid
Prevention of HTML/invalid chars in host param
π¨ CVE-2020-10194
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.
π@cveNotify
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.
π@cveNotify
GitHub
ZBUG-1094:Broken GAL search filtering Β· Zimbra/zm-mailbox@1df440e
zm-mailbox for Zimbra Collaboration Suite, FOSS Edition - Zimbra/zm-mailbox
π¨ CVE-2019-11574
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
π@cveNotify
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
π@cveNotify
π¨ CVE-2020-10799
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
π@cveNotify
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
π@cveNotify
GitHub
No disabling external entity expansion (XXE) Β· Issue #229 Β· deeplook/svglib
Hi! I found that I can perform XXE attack (https://en.wikipedia.org/wiki/XML_external_entity_attack) when using svg2rlg function Code: saved_image_path = 'test_png.png' with open("./te...
π¨ CVE-2013-7487
On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to βsystemβ, which allows remote attackers to execute arbitrary code via TCP port 9000.
π@cveNotify
On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to βsystemβ, which allows remote attackers to execute arbitrary code via TCP port 9000.
π@cveNotify
Blogspot
Swann Song - DVR Insecurity
"Swan song" is a metaphorical phrase for a final gesture, effort, or performance given just before death or retirement. This post serves as ...
π¨ CVE-2019-12767
An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.
π@cveNotify
An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.
π@cveNotify
π¨ CVE-2019-17185
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack.
π@cveNotify
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack.
π@cveNotify
www.freeradius.org
Security Notifications
The world's leading RADIUS server. The project includes a GPL AAA server, BSD licensed client and PAM and Apache modules. Full support is available from InkBridge Networks.
π¨ CVE-2019-18936
UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches an inconsistent state) via input data that triggers an error.
π@cveNotify
UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches an inconsistent state) via input data that triggers an error.
π@cveNotify
GitHub
jgarzik/univalue
High performance RAII C++ JSON library and universal value object class - jgarzik/univalue