Security
Headlines
HeadlinesLatestCVEs

Tag

#google

Adult Video Script 3.0 File Inclusion

Adult Video Script version 3.0 suffers from local and remote file inclusion vulnerabilities.

Packet Storm
#vulnerability#web#windows#google#php#auth#firefox
Adiscon LogAnalyzer 4.1.5 Cross Site Scripting

Adiscon LogAnalyzer version 4.1.5 suffers from a cross site scripting vulnerability.

Adapt Inventory Management System 1.0.0 SQL Injection

Adapt Inventory Management System version 1.0.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Active Newspaper 2.0 HTML Injection

Active Newspaper version 2.0 suffers from an html injection vulnerability.

Ubuntu Security Notice USN-6186-1

Ubuntu Security Notice 6186-1 - Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Gwangun Jung discovered that the Quick Fair Queueing scheduler implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.

Ubuntu Security Notice USN-6185-1

Ubuntu Security Notice 6185-1 - It was discovered that the TUN/TAP driver in the Linux kernel did not properly initialize socket data. A local attacker could use this to cause a denial of service. It was discovered that the Real-Time Scheduling Class implementation in the Linux kernel contained a type confusion vulnerability in some situations. A local attacker could use this to cause a denial of service.

Millions of Repos on GitHub Are Potentially Vulnerable to Hijacking

Many organizations are unwittingly exposing users of their code repositories to repojacking when renaming projects, a new study shows.

Mullvad VPN Introduces Mullvad Leta: A Privacy-Focused Search Engine

By Waqas The Mullvad Leta search engine is accessible exclusively to users with a paid Mullvad VPN account. This is a post from HackRead.com Read the original post: Mullvad VPN Introduces Mullvad Leta: A Privacy-Focused Search Engine

Growing SaaS Usage Means Larger Attack Surface

Software-as-a-service has its benefits, but abandoned SaaS integrations and idle data sharing introduce risk to the enterprise.

Azure AD 'Log in With Microsoft' Authentication Bypass Affects Thousands

The "nOAuth" attack allows cross-platform spoofing and full account takeovers, and enterprises need to remediate the issue immediately, researchers warn.