Security
Headlines
HeadlinesLatestCVEs

Tag

#pdf

Massive China-Linked Disinformation Campaign Taps PR Firm for Help

A global network of inauthentic news sites present themselves as independent news outlets, offering content favoring China's government and articles critical of the US.

DARKReading
#web#ios#intel#pdf#bios#auth
Deep Instinct Pioneers Deep-Learning Malware Prevention to Protect Mission-Critical Business Applications at Scale

Agentless approach meets the attacker earlier to protect financial services and other large enterprises from an underserved attack vector.

CVE-2022-36197: A stored cross-site scripting (XSS) vulnerability exists in BigTree CMS 4.4.16 · Issue #392 · bigtreecms/BigTree-CMS

BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.

GHSA-32fw-9wq8-9x9c: node-latex-pdf is susceptible to command injection

A command injection vulnerability affects all versions of the package node-latex-pdf.

CVE-2020-28433: Snyk Vulnerability Database | Snyk

This affects all versions of package node-latex-pdf.

New DawDropper Malware Targeting Android Devices via Play Store

By Waqas According to Trend Micro researchers, the DawDropper aims at stealing user data, in particular from banking apps on… This is a post from HackRead.com Read the original post: New DawDropper Malware Targeting Android Devices via Play Store

mPDF 7.0 Local File Inclusion

mPDF version 7.0 suffers from a local file inclusion vulnerability.

CVE-2022-27864: Security Advisories | Autodesk Trust Center

A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Geonetwork 4.2.0 XML Injection

Geonetwork versions 3.1.x through 4.2.0 suffer from an XML external entity injection vulnerability.

Over a Dozen Android Apps on Google Play Store Caught Dropping Banking Malware

A malicious campaign leveraged seemingly innocuous Android dropper apps on the Google Play Store to compromise users' devices with banking malware. These 17 dropper apps, collectively dubbed DawDropper by Trend Micro, masqueraded as productivity and utility apps such as document scanners, QR code readers, VPN services, and call recorders, among others. All these apps in question have been