Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.
Published at: October 01, 2020 at 05:15AM
View on website
Showing posts with label government. Show all posts
Showing posts with label government. Show all posts
Wednesday, September 30, 2020
New vulnerability on the NVD: CVE-2019-20903
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
Published at: October 01, 2020 at 05:15AM
View on website
Published at: October 01, 2020 at 05:15AM
View on website
New vulnerability on the NVD: CVE-2020-12505
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852 version FW07 and prior versions. WAGO 750-880/xxx-xxx version FW07 and prior versions. WAGO 750-881 version FW07 and prior versions. WAGO 750-831/xxx-xxx version FW07 and prior versions. WAGO 750-882 version FW07 and prior versions. WAGO 750-885/xxx-xxx version FW07 and prior versions. WAGO 750-889 version FW07 and prior versions.
Published at: September 30, 2020 at 07:15PM
View on website
Published at: September 30, 2020 at 07:15PM
View on website
New vulnerability on the NVD: CVE-2020-12506
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362 version FW03 and prior versions. WAGO 750-363 version FW03 and prior versions. WAGO 750-823 version FW03 and prior versions. WAGO 750-832/xxx-xxx version FW03 and prior versions. WAGO 750-862 version FW03 and prior versions. WAGO 750-891 version FW03 and prior versions. WAGO 750-890/xxx-xxx version FW03 and prior versions.
Published at: September 30, 2020 at 07:15PM
View on website
Published at: September 30, 2020 at 07:15PM
View on website
New vulnerability on the NVD: CVE-2019-17098
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior versions on Android. August Connect Firmware version 2.2.12 and prior versions.
Published at: September 30, 2020 at 04:15PM
View on website
Published at: September 30, 2020 at 04:15PM
View on website
Friday, September 25, 2020
New vulnerability on the NVD: CVE-2018-6447
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account.
Published at: September 25, 2020 at 05:15PM
View on website
Published at: September 25, 2020 at 05:15PM
View on website
New vulnerability on the NVD: CVE-2018-6448
A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.
Published at: September 25, 2020 at 05:15PM
View on website
Published at: September 25, 2020 at 05:15PM
View on website
New vulnerability on the NVD: CVE-2018-6449
Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers
Published at: September 25, 2020 at 05:15PM
View on website
Published at: September 25, 2020 at 05:15PM
View on website
New vulnerability on the NVD: CVE-2019-11556
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
Published at: September 25, 2020 at 09:15AM
View on website
Published at: September 25, 2020 at 09:15AM
View on website
Thursday, September 24, 2020
New vulnerability on the NVD: CVE-2017-17477
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
Published at: September 25, 2020 at 07:23AM
View on website
Published at: September 25, 2020 at 07:23AM
View on website
New vulnerability on the NVD: CVE-2018-10432
Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
Published at: September 25, 2020 at 07:23AM
View on website
Published at: September 25, 2020 at 07:23AM
View on website
New vulnerability on the NVD: CVE-2018-10585
Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
Published at: September 25, 2020 at 07:23AM
View on website
Published at: September 25, 2020 at 07:23AM
View on website
Wednesday, September 23, 2020
New vulnerability on the NVD: CVE-2015-4719
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
Published at: September 24, 2020 at 05:15AM
View on website
Published at: September 24, 2020 at 05:15AM
View on website
Tuesday, September 22, 2020
New vulnerability on the NVD: CVE-2019-15957
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system. When processed, the commands will be executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by providing malicious input to a specific field in the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system as the root user.
Published at: September 23, 2020 at 04:15AM
View on website
Published at: September 23, 2020 at 04:15AM
View on website
New vulnerability on the NVD: CVE-2019-15959
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context.
Published at: September 23, 2020 at 04:15AM
View on website
Published at: September 23, 2020 at 04:15AM
View on website
New vulnerability on the NVD: CVE-2019-15963
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software. The vulnerability is due to insufficient protection of user-supplied input by the web-based management interface of the affected service. An attacker could exploit this vulnerability by accessing the interface and viewing restricted portions of the software configuration. A successful exploit could allow the attacker to gain access to sensitive information or conduct further attacks.
Published at: September 23, 2020 at 04:15AM
View on website
Published at: September 23, 2020 at 04:15AM
View on website
New vulnerability on the NVD: CVE-2019-15969
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script or HTML code in the context of the interface, which could allow the attacker to gain access to sensitive, browser-based information.
Published at: September 23, 2020 at 04:15AM
View on website
Published at: September 23, 2020 at 04:15AM
View on website
New vulnerability on the NVD: CVE-2019-15974
A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. A successful exploit could allow the attacker to redirect a user to a malicious web page. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.
Published at: September 23, 2020 at 04:15AM
View on website
Published at: September 23, 2020 at 04:15AM
View on website
New vulnerability on the NVD: CVE-2019-15992
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is due to insufficient restrictions on the allowed Lua function calls within the context of user-supplied Lua scripts. A successful exploit could allow the attacker to trigger a heap overflow condition and execute arbitrary code with root privileges on the underlying Linux operating system of an affected device.
Published at: September 23, 2020 at 04:15AM
View on website
Published at: September 23, 2020 at 04:15AM
View on website
New vulnerability on the NVD: CVE-2019-15993
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.
Published at: September 23, 2020 at 04:15AM
View on website
Published at: September 23, 2020 at 04:15AM
View on website
Subscribe to:
Posts (Atom)