Security
Headlines
HeadlinesLatestCVEs

Tag

#ubuntu

Sophos UTM WebAdmin SID Command Injection

This Metasploit module exploits an SID-based command injection in Sophos UTM's WebAdmin interface to execute shell commands as the root user.

Packet Storm
#web#red_hat#ubuntu#web
Backdoor.Win32.Prorat.ntz Weak Hardcoded Password

Backdoor.Win32.Prorat.ntz malware suffers from having a weak hardcoded password.

Backdoor.Win32.Prorat.ntz Man-In-The-Middle

Backdoor.Win32.Prorat.ntz malware suffers from a man-in-the-middle vulnerability.

Microsoft OMI Management Interface Authentication Bypass

By removing the authentication header, an attacker can issue an HTTP request to the OMI management endpoint that will cause it to execute an operating system command as the root user. This vulnerability was patched in OMI version 1.6.8-1 (released September 8th 2021).

Apple Security Advisory 2021-10-26-11

Apple Security Advisory 2021-10-26-11 - tvOS 15 addresses bypass, code execution, denial of service, out of bounds read, and use-after-free vulnerabilities.

Apple Security Advisory 2021-10-26-10

Apple Security Advisory 2021-10-26-10 - watchOS 8 addresses bypass, code execution, denial of service, out of bounds read, and use-after-free vulnerabilities.

Apple Security Advisory 2021-10-26-9

Apple Security Advisory 2021-10-26-9 - iOS 15 and iPadOS 15 addresses code execution, denial of service, out of bounds read, spoofing, and use-after-free vulnerabilities.