Security
Headlines
HeadlinesLatestCVEs

Tag

#chrome

CVE-2023-29915: H3C Magic R200 was discovered stack overflow via CMD parameter at /goform/aspForm - HackMD

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via CMD parameter at /goform/aspForm.

CVE
#vulnerability#web#mac#windows#apple#dos#buffer_overflow#auth#chrome#webkit
N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX

The supply chain attack targeting 3CX was the result of a prior supply chain compromise associated with a different company, demonstrating a new level of sophistication with North Korean threat actors. Google-owned Mandiant, which is tracking the attack event under the moniker UNC4736, said the incident marks the first time it has seen a "software supply chain attack lead to another software

Update now, there's a Chrome zero-day in the wild

Categories: News Tags: chrome Tags: browser Tags: update Tags: vulnerability Tags: CVE Tags: exploit Tags: exploitation Tags: zero-day Users of Chrome should ensure they're running the latest version to patch an integer overflow in the Skia graphics library. (Read more...) The post Update now, there's a Chrome zero-day in the wild appeared first on Malwarebytes Labs.

3CX Supply Chain Attack Tied to Financial Trading App Breach

Mandiant found that North Korea's UNC4736 gained initial access on 3CX's network when an employee downloaded a weaponized but legitimately-signed app from Trading Technologies.

Chitor-CMS 1.1.2 SQL Injection

Chitor-CMS version 1.1.2 suffers from a remote SQL injection vulnerability.

ProjeQtOr Project Management System 10.3.2 Shell Upload

ProjeQtOr Project Management System version 10.3.2 suffers from a remote shell upload vulnerability.

Piwigo 13.6.0 Cross Site Scripting

Piwigo version 13.6.0 suffers from a persistent cross site scripting vulnerability.

Swagger UI 4.1.3 Critical Information Misrepresentation

Swagger UI version 4.1.3 user interface misrepresentation of information proof of concept exploit.