Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

Backdoor.Win32.Autocrat.b MVID-2022-0660 Weak Hardcoded Credential

Backdoor.Win32.Autocrat.b malware suffers from a weak hardcoded credential vulnerability.

Packet Storm
#vulnerability#web#windows#microsoft#redis#backdoor#auth
Ubuntu Security Notice USN-5742-1

Ubuntu Security Notice 5742-1 - It was discovered that JBIG-KIT incorrectly handled decoding certain large image files. If a user or automated system using JBIG-KIT were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service.

Win32.Ransom.Conti MVID-2022-0662 Cryptography Logic Flaw

Win32.Ransom.Conti ransomware fails to encrypt non PE files that have a ".exe" in the filename. Creating specially crafted file names successfully evaded encryption for this malware sample.

Trojan.Win32.DarkNeuron.gen MVID-2022-0661 Named Pipe NULL DACL

Trojan.Win32.DarkNeuron.gen malware creates an IPC pipe with a NULL DACL allowing RW for the Everyone user.

Ubuntu Security Notice USN-5741-1

Ubuntu Security Notice 5741-1 - It was discovered that Exim incorrectly handled certain regular expressions. An attacker could use this issue to cause Exim to crash, resulting in a denial of service, or possibly execute arbitrary code.

Helmet Store Showroom 1.0 SQL Injection

Helmet Store Showroom version 1.0 suffers from an authenticated remote SQL injection vulnerability.

Sanitization Management System 1.0 SQL Injection

Sanitization Management System version 1.0 suffers from a remote SQL injection vulnerability.

Chrome blink::LocalFrameView::PerformLayout Use-After-Free

Chrome suffers from a heap use-after-free vulnerability in blink::LocalFrameView::PerformLayout due to an incomplete fix for CVE-2022-3199.

XNU vm_object Use-After-Free

XNU suffers from a vm_object use-after-free vulnerability due to invalid error handling in vm_map_enter.

XNU Dangling PTE Entry

XNU suffers from a dangling PTE entry due to integer truncation when collapsing vm_object shadow chains.