Security
Headlines
HeadlinesLatestCVEs

Tag

#google

Staggering growth of cybercrime and how data science helps improve online security

By Waqas If you were to compare the money generated by cybercrime with the GDP of world nations, it would come third behind the economic powerhouses of America and China. This is a post from HackRead.com Read the original post: Staggering growth of cybercrime and how data science helps improve online security

HackRead
#Cyber Crime#Cyber Attack#hacking#Purple team#security#Vulnerability#Hacking News#China#cyber security#hacking#Pwn2Own#security#Vulnerability#windows#linux#Security#cloud#Cyber Attack#Cyber Crime#cyber security#hacking#security#Vulnerability#Malware#Scams and Fraud#Security#Adblocker#Chrome#Fraud#Google#Scam#security#web#google#Gaming#Malware#Security#gaming#Minecraft#security#Cyber Attacks#Cyber Crime#Security#CISA#FBI#NSA#Ransomware#scada#USA#Cyber Crime#Security#Data Science#hacking#Malware#Phishing#Ransomware#security
CVE-2021-42227: There is a stored xss vulnerability in kindeditor - 4.1.* · Issue #336 · kindsoft/kindeditor

Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).

CVE-2021-22963: HackerOne

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.

CVE-2021-3882: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ledgersmb

LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB 1.8 and newer switched from Basic authentication to using cookie authentication with encrypted cookies. Although an attacker can't access the information inside the cookie, nor the password of the user, possession of the cookie is enough to access the application as the user from which the cookie has been obtained. In order for the attacker to obtain the cookie, first of all the server must be configured to respond to unencrypted requests, the attacker must be suitably positioned to eavesdrop on the network traffic between the client and the server *and* the user must be tricked into using unencrypted HTTP traffic. Proper audit control and separation of duties limit Integr...

CVE-2021-25738: [Kubernetes Java Client] CVE-2021-25738: Code exec via yaml parsing

Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

CVE-2021-37975: Stable Channel Update for Desktop

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30632

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.