Skip to content
GeekWire
  • Home
  • News
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • Security
    • Books
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • Archive
  • About
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap
GeekWire
  • Home
  • News
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • Security
    • Books
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • Archive
  • About
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

CERT

VU#434904: Dnsmasq is vulnerable to memory corruption and cache poisoning

19 January 2021

Overview

Dnsmasq is vulnerable to a set of memory corruption issues handling DNSSEC data and a second set of issues validating …

Tags CERT

VU#843464: SolarWinds Orion API authentication bypass allows remote command execution

27 December 2020

Overview

The SolarWinds Orion API is vulnerable to authentication bypass that could allow a remote attacker to execute API …

Tags CERT

VU#843464: SolarWinds Orion API authentication bypass allows remote comand execution

26 December 2020

Overview

The SolarWinds Orion API is vulnerable to authentication bypass that could allow a remote attacker to execute API …

Tags CERT

VU#429301: Veritas Backup Exec is vulnerable to privilege escalation due to OPENSSLDIR location

23 December 2020

Overview

Veritas Backup Exec contains a privilege escalation vulnerability due to the use of an OPENSSLDIR …

Tags CERT

VU#815128: Embedded TCP/IP stacks have memory corruption vulnerabilities

8 December 2020

Overview

Multiple open-source embedded TCP/IP stacks, commonly used in Internet of Things (IoT) and embedded devices, have …

Tags CERT

VU#724367: VMware Workspace ONE Access and related components are vulnerable to command injection

23 November 2020

Overview

VMware Workspace One Access, Access Connector, …

Tags CERT

VU#231329: Replay Protected Memory Block (RPMB) protocol does not adequately defend against replay attacks

10 November 2020

Overview

The Replay Protected Memory Block (RPMB) protocol found in several storage specifications does not securely protect …

Tags CERT

VU#208577: Chocolatey Boxstarter is vulnerable to privilege escalation due to weak ACLs

9 November 2020

Overview

Chocolatey Boxstarter fails to properly set ACLs, which can allow an unprivileged Windows user to be able to run …

Tags CERT

VU#760767: Macrium Reflect is vulnerable to privilege escalation due to OPENSSLDIR location

29 October 202026 October 2020

Overview

Macrium Reflect contains a privilege escalation vulnerability due to the use of an OPENSSLDIR variable …

Tags CERT

VU#208577: Chocolatey Boxstarter vulnerable to privilege escalation due to weak ACLs

29 October 202022 October 2020

Overview

Chocolatey Boxstarter fails to properly set ACLs, which can allow an unprivileged Windows user to be able to run …

Tags CERT

VU#114757: Acronis backup software contains multiple privilege escalation vulnerabilities

29 October 202012 October 2020

Overview

Acronis True Image, Cyber Backup, and Cyber Protection all contain privilege escalation vulnerabilities, which can …

Tags CERT

VU#490028: Microsoft Windows Netlogon Remote Protocol (MS-NRPC) uses insecure AES-CFB8 initialization vector

29 October 202016 September 2020

Overview

The Microsoft Windows Netlogon Remote Protocol (MS-NRPC) reuses a known, static, zero-value initialization vector (IV) …

Tags CERT
Post navigation
Older posts
Page1 Page2 … Page16 Next →
Cookie-Free

NVD

CVE-2020-17532 – When handler-router component is enabled in servicecomb-java-chassis, authenticated user m …

25 January 2021

CVE-2021-23901 – An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParse …

25 January 2021

CVE-2020-28487 – This affects the package vis-timeline before 7.4.4. An attacker with the ability to contr …

22 January 2021

CVE-2020-4766 – IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of servi …

22 January 2021

CVE-2021-21259 – HedgeDoc is open source software which lets you create real-time collaborative markdown no …

22 January 2021

CVE-2021-21260 – Online Invoicing System (OIS) is open source software which is a lean invoicing system for …

22 January 2021

EXPLOITS

Klog Server 2.4.1 – Unauthenticated Command Injection (Metasploit)

25 January 2021

Library System 1.0 – ‘category’ SQL Injection

25 January 2021

CASAP Automated Enrollment System 1.0 – ‘route’ Stored XSS

25 January 2021

CASAP Automated Enrollment System 1.0 – ‘First Name’ Stored XSS

25 January 2021

Collabtive 3.1 – ‘address’ Persistent Cross-Site Scripting

25 January 2021

MyBB Timeline Plugin 1.0 – Cross-Site Scripting / CSRF

25 January 2021

SECURELIST

Sunburst backdoor – code overlaps with Kazuar

11 January 2021

Digital Footprint Intelligence Report

29 December 2020

How we protect our users against the Sunburst backdoor

23 December 2020

Lazarus covets COVID-19-related intelligence

23 December 2020

Sunburst: connecting the dots in the DNS requests

18 December 2020

The future of cyberconflicts

18 December 2020

Information Cyber Network Enterprise Security News

© 2021 GeekWire | Privacy Policy | Cookie-Free | We are not responsible for the content of external sites.