Plus récents

APSB22-02 - Adobe Illustrator : This update resolves an important and a moderate vulnerability that could lead to privilege escalation.

helpx.adobe.com/security/produ

APSB22-05 - Adobe InDesign : Successful exploitation could lead to arbitrary code execution and privilege escalation.

helpx.adobe.com/security/produ

💥 High severity flaw in the KCodes NetUSB kernel module used by a large number of network device vendors and affecting millions of end user router devices. Attackers could remotely exploit this vulnerability to execute code in the kernel.

sentinelone.com/labs/cve-2021-

8 different security vulnerabilities arising from inconsistencies among 16 different URL parsing libraries could allow denial-of-service (DoS) conditions, information leaks and remote code execution (RCE) in various web applications, researchers are warning

threatpost.com/url-parsing-bug

WordPress 5.8.3 Security Release This security release features four (4) security fixes. (CVE-2022-21661, CVE-2022-21662, CVE-2022-21663, CVE-2022-21664)

wordpress.org/news/2022/01/wor

CVE-2021-42392 : The JNDI Strikes Back – Unauthenticated RCE in H2 Database Console. H2 is a very popular open-source Java SQL database. Notes: newer versions of Java contain the trustURLCodebase mitigation that will not allow remote codebases to be loaded naively via JNDI. However, this mitigation is not bulletproof..

jfrog.com/blog/the-jndi-strike

A Romanian vulnerability researcher has discovered more than 70 cache poisoning vulnerabilities in combinations of cloud applications and content delivery networks (CDNs) that could be used for denial-of-service attacks on the applications.

youst.in/posts/cache-poisoning

How Log4j vulnerabilities affect a lot of devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.

trendmicro.com/en_us/research/

L'agence fédérale américaine du commerce (FTC) gonfle ses muscles afin de créer un rapport de force en menaçant d'utiliser toute son autorité légale pour poursuivre en justice les entreprises qui ne protégent pas les données des consommateurs contre l'exposition à des vulnérabilités connues

lemondeinformatique.fr/actuali

CVE-2021-20047 - SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in RCE in the target system.

cyberis.co.uk/blog/CVE-2021-20

Plus anciens