Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2023-40036: GHSL-2023-112, GHSL-2023-102, GHSL-2023-103, GHSL-2023-092: Buffer Overflows in Notepad++ - CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.

CVE
#mac#windows#git#buffer_overflow#ssl
Gusto Recipes Management 1.5.1 Insecure Settings

Gusto Recipes Management version 1.5.1 suffers from an ignored default credential vulnerability.

Groupoffice 3.4.21 Directory Traversal

Groupoffice version 3.4.21 suffers from a directory traversal vulnerability.

Grawlix CMS 1.1.1 Cross Site Scripting

Grawlix CMS version 1.1.1 suffers from a cross site scripting vulnerability.

Gravigra CMS 1.0 SQL Injection

Gravigra CMS version 1.0 suffers from a remote SQL injection vulnerability.

Global Domains International 2.0 HTML Injection

Global Domains International version 2.0 suffers from an html injection vulnerability.

GetSimple CMS 3.3.2 Cross Site Scripting

GetSimple CMS version 3.3.2 suffers from a cross site scripting vulnerability.

G And G Corporate CMS 1.0 SQL Injection

G and G Corporate CMS version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Update now! Google Chrome's first weekly update has arrived

Categories: Exploits and vulnerabilities Tags: stable channel Tags: weekly updates Tags: CVE-2023-4427 Tags: CVE-2023-4428 Tags: CVE-2023-4429 Tags: CVE-2023-4430 Tags: CVE-2023-4431 Tags: use after free Tags: out of bounds Tags: heap corruption The first of Chrome's now weekly security updates fixes five vulnerabilities. (Read more...) The post Update now! Google Chrome's first weekly update has arrived appeared first on Malwarebytes Labs.

China-Linked Flax Typhoon Cyber Espionage Targets Taiwan's Key Sectors

A nation-state activity group originating from China has been linked to cyber attacks on dozens of organizations in Taiwan as part of a suspected espionage campaign. The Microsoft Threat Intelligence team is tracking the activity under the name Flax Typhoon, which is also known as Ethereal Panda. "Flax Typhoon gains and maintains long-term access to Taiwanese organizations' networks with minimal