Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Wednesday, September 30, 2020

John Jason Fallows



This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are as essential for the working of basic functionalities of the website.

from Pocket https://ift.tt/30nIFHl
via IFTTT

John Jason Fallows



This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are as essential for the working of basic functionalities of the website.

from Pocket https://ift.tt/3n7SEtV
via IFTTT

John Jason Fallows



This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are as essential for the working of basic functionalities of the website.

from Pocket https://ift.tt/3l5Vhef
via IFTTT

Friday, September 4, 2020

New vulnerability on the NVD: CVE-2019-20916



The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.

from Pocket https://ift.tt/2ZaJFhv
via IFTTT

Thursday, September 3, 2020

New vulnerability on the NVD: CVE-2019-11928



An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.

from Pocket https://ift.tt/2EOrV4F
via IFTTT

Monday, August 17, 2020

New vulnerability on the NVD: CVE-2017-8986



** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

from Pocket https://ift.tt/2E8ONuX
via IFTTT

New vulnerability on the NVD: CVE-2017-8995



** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

from Pocket https://ift.tt/2CGenag
via IFTTT

New vulnerability on the NVD: CVE-2017-8996



** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

from Pocket https://ift.tt/3aCwISa
via IFTTT

New vulnerability on the NVD: CVE-2017-8997



** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

from Pocket https://ift.tt/2Yru9xt
via IFTTT

New vulnerability on the NVD: CVE-2017-8998



** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

from Pocket https://ift.tt/316qYww
via IFTTT

New vulnerability on the NVD: CVE-2017-8999



** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

from Pocket https://ift.tt/31ZWqvY
via IFTTT

New vulnerability on the NVD: CVE-2017-9004



** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

from Pocket https://ift.tt/3iSTIiK
via IFTTT

Tuesday, August 11, 2020

New vulnerability on the NVD: CVE-2020-0258



In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploitation.

from Pocket https://ift.tt/3fPlmv5
via IFTTT

New vulnerability on the NVD: CVE-2020-0259



In android_verity_ctr of dm-android-verity.c, there is a possible way to modify a dm-verity protected filesystem due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

from Pocket https://ift.tt/2PIYB1h
via IFTTT

New vulnerability on the NVD: CVE-2020-0260



Published at: August 11, 2020 at 04:15PM View on website

from Pocket https://ift.tt/2DMDw3k
via IFTTT

New vulnerability on the NVD: CVE-2020-10777



A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.

from Pocket https://ift.tt/2FdbZZj
via IFTTT

New vulnerability on the NVD: CVE-2020-10778



In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.

from Pocket https://ift.tt/3kC5lfu
via IFTTT

New vulnerability on the NVD: CVE-2020-10780



Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events.

from Pocket https://ift.tt/31BLqo4
via IFTTT

New vulnerability on the NVD: CVE-2020-10780



Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events.

from Pocket https://ift.tt/3kxfKsZ
via IFTTT

Saturday, August 8, 2020

New vulnerability on the NVD: CVE-2019-19704



In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.

from Pocket https://ift.tt/3gI1smX
via IFTTT