Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2022-29457: ADSelfService Plus Release Notes

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

CVE
#sql#xss#csrf#vulnerability#web#ios#android#mac#windows#apple#google#microsoft#ubuntu#linux#cisco#dos#apache#js#java#oracle#intel#rce#perl#ldap#ssrf#log4j#oauth#auth#ibm#postgres#chrome#firefox#sap#ssl
CVE-2022-29457: ADSelfService Plus Release Notes

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

CVE-2021-3624: #984761 - dcraw: CVE-2021-3624: buffer-overflow caused by integer-overflow in foveon_load_camf()

There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.

New Hacking Campaign Targeting Ukrainian Government with IcedID Malware

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new wave of social engineering campaigns delivering IcedID malware and leveraging Zimbra exploits with the goal of stealing sensitive information. Attributing the IcedID phishing attacks to a threat cluster named UAC-0041, the agency said the infection sequence begins with an email containing a Microsoft Excel document (

Google Emergency Update Fixes Chrome Zero-Day

Google patches a critical flaw in its Chrome browser, bringing its count of zero-day vulnerabilities fixed in 2022 to four.

CVE-2022-23292

Microsoft Power BI Spoofing Vulnerability.

CVE-2022-24472

Microsoft SharePoint Server Spoofing Vulnerability.

CVE-2022-24548

Microsoft Defender Denial of Service Vulnerability.

CVE-2022-24472

Microsoft SharePoint Server Spoofing Vulnerability.

CVE-2022-24473

Microsoft Excel Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-26901.