Posts

Showing posts with the label hacking

Red Hat Security Advisory 2021-4946-03

Red Hat Security Advisory 2021-4946-03 - Network Security Services is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. from Packet Storm https://ift.tt/3rK3knA

Founder Of Massive Robo Text Service Accused Of Running Secret Spying Operation

from Packet Storm https://ift.tt/3IoqZzT

runc / libcontainer Bind Mount Sources Insecure Handling

The recent commit #9c4440 introduces two vulnerabilities to libcontainer that can be exploited by an attacker with partial control over the bind mount sources of a new container. from Packet Storm https://ift.tt/2ZXA6WE

Ubuntu Security Notice USN-5171-1

Ubuntu Security Notice 5171-1 - It was discovered that Long Range ZIP incorrectly handled certain specially crafted lrz files. A remote attacker could possibly use this issue to cause a denial of service or other unspecified impact. from Packet Storm https://ift.tt/31xdlK2

Auerswald COMpact 8.0B Privilege Escalation

RedTeam Pentesting discovered a vulnerability in the web-based management interface of the Auerswald COMpact 5500R PBX which allows low-privileged users to access passwords of administrative user accounts. Affected versions include 8.0B and below. from Packet Storm https://ift.tt/3In1bE1

Auerswald COMfortel 1400/2600/3600 IP 2.8F Authentication Bypass

RedTeam Pentesting discovered a vulnerability in the web-based configuration management interface of the Auerswald COMfortel 1400 and 2600 IP desktop phones. The vulnerability allows accessing configuration data and settings in the web-based management interface without authentication. Versions 2.8F and below are affected. from Packet Storm https://ift.tt/3Gj1r5f

Croogo 3.0.2 Remote Code Execution

Croogo version 3.0.2 suffers from an authenticated remote code execution vulnerability. from Packet Storm https://ift.tt/3IpM1hd

Microsoft Internet Explorer Active-X Control Security Bypass

Microsoft Internet Explorer suffers from an active-x related bypass vulnerability. Microsoft will not address the issue as it is end of life. from Packet Storm https://ift.tt/3EzgWp9

Ubuntu Security Notice USN-5174-1

Ubuntu Security Notice 5174-1 - Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client connections. A remote attacker could possibly use this issue to downgrade connections to plaintext authentication. Andrew Bartlett discovered that Samba incorrectly mapping domain users to local users. An authenticated attacker could possibly use this issue to become root on domain members. Andrew Bartlett discovered that Samba did not properly check sensitive attributes. An authenticated attacker could possibly use this issue to escalate privileges. Various other issues were also addressed. from Packet Storm https://ift.tt/3rLwQJH

HCL Lotus Notes 12 Unquoted Service Path

HCL Lotus Notes version 12 suffers from an unquoted service path vulnerability. from Packet Storm https://ift.tt/3DthPhI

Simple Online Men's Salon Management System 1.0 SQL Injection

Simple Online Men's Salon Management System version 1.0 appears to suffer from a time-based remote SQL injection vulnerability. from Packet Storm https://ift.tt/3GivI4e

American Diplomat's iPhones Compromised By NSO Group

from Packet Storm https://ift.tt/3Irz5r8

FBI: Cuban Ransomware Hits 49 Critical Infrastructure Organizations

from Packet Storm https://ift.tt/3rEbZaY

BitMart Crypto Exchange Loses $150 Million To Hackers

from Packet Storm https://ift.tt/3GiQyQV

SolarWinds Hackers Keep Compromising Targets

from Packet Storm https://ift.tt/3lCvkW4

OrbiTeam BSCW Server XSS / LFI / User Enumeration

OrbiTeam BSCW Server versions 5.0.x, 5.1.x, 5.2.4 and below, 7.3.x and below, and 7.4.3 and below suffer from path traversal, cross site scripting, HTTP header, session object manipulation, local file inclusion, and user enumeration vulnerabilities. from Packet Storm https://ift.tt/3ElAWvi

Red Hat Security Advisory 2021-4913-04

Red Hat Security Advisory 2021-4913-04 - Mailman is a program used to help manage e-mail discussion lists. Issues addressed include bypass and cross site request forgery vulnerabilities. from Packet Storm https://ift.tt/3ppji3x

Red Hat Security Advisory 2021-4827-06

Red Hat Security Advisory 2021-4827-06 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Issues addressed include a bypass vulnerability. from Packet Storm https://ift.tt/31pMJdt

Backdoor.Win32.WinShell.50 Hardcoded Password

Backdoor.Win32.WinShell.50 malware suffers from a hard-coded password vulnerability. from Packet Storm https://ift.tt/3Dg4UzH

WordPress All-In-One Video Gallery 2.4.9 Local File Inclusion

WordPress All-In-One Video Gallery plugin versions 2.4.9 and below suffer from a local file inclusion vulnerability. from Packet Storm https://ift.tt/3xQw6nm