Security
Headlines
HeadlinesLatestCVEs

Tag

#chrome

RedEnergy Stealer-as-a-Ransomware Threat Targeting Energy and Telecom Sectors

A sophisticated stealer-as-a-ransomware threat dubbed RedEnergy has been spotted in the wild targeting energy utilities, oil, gas, telecom, and machinery sectors in Brazil and the Philippines through their LinkedIn pages. The malware "possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive data, while also incorporating different modules for

The Hacker News
#web#mac#google#microsoft#java#auth#chrome#firefox#The Hacker News
POS Codekop 2.0 Shell Upload

POS Codekop version 2.0 suffers from a remote shell upload vulnerability.

CVE-2023-3133: Tutor LMS – eLearning and online course solution

The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.

CVE-2023-3497

Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)

Chrome Mojo Message Validation Bypass

During a Mojo IPC method call, there are multiple stages of validation and deserialization that take place. These assume that the contents of the message cannot be modified during the deserialization process, but the new core_ipcz implementation returns message contents directly in shared memory.

CVE-2021-34506

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2021-34475

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVE-2021-31982

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2021-42307

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Debian Security Advisory 5440-1

Debian Linux Security Advisory 5440-1 - Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.