Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

OpenSSH 9.1p1

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Packet Storm
#linux#ssh
Backdoor.Win32.Delf.eg MVID-2022-0647 Remote Command Execution

Backdoor.Win32.Delf.eg malware suffers from an unauthenticated remote command execution vulnerability.

Joomla Rentalot Plus 19.05 Cross Site Scripting

Joomla Rentalot Plus extension version 19.05 suffers from a cross site scripting vulnerability.

Backdoor.Win32.NTRC MVID-2022-0646 Hardcoded Credential

Backdoor.Win32.NTRC malware suffers from a hardcoded credential vulnerability.

Password Manager For IIS 2.0 Cross Site Scripting

Password Manager for IIS version 2.0 suffers from a cross site scripting vulnerability.

Joomla MarvikShop ShoppingCart 3.4 Cross Site Scripting

Joomla MarvikShop ShoppingCart extension version 3.4 suffers from a suffers from a cross site scripting vulnerability.

Joomla MarvikShop ShoppingCart 3.4 SQL Injection

Joomla MarvikShop ShoppingCart extension version 3.4 suffers from a remote SQL injection vulnerability.

Google Chrome 103.0.5060.53 network::URLLoader::NotifyCompleted Heap Use-After-Free

Google Chrome version 103.0.5060.53 (Official Build) and Chromium version 105.0.5148.0 (Developer Build) (64-bit) suffer from a network::URLLoader::NotifyCompleted heap use-after-free vulnerability.

Google Chrome 103.0.5060.53 Autofill Assistant Universal Cross Site Scripting

Google Chrome version 103.0.5060.53 suffers from an Autofill Assistant universal cross site scripting vulnerability.

Windows Kerberos RC4 MD4 Encryption Downgrade Privilege Escalation

The Windows KDC allows an interposing attacker to downgrade to RC4 MD4 encryption in compromising the user's TGT session key resulting in escalation of privilege.