Tag
#windows
Categories: News Tags: TikTok Tags: Super FabriXss Tags: Twitter Tags: macOS malware Tags: ransomware Tags: 2023 State of Malware Tags: Western Digital Tags: Android Tags: endpoint security Tags: ChatGPT Tags: K-12 Tags: IoT Tags: Facebook Tags: targeted advertising Tags: Google Tags: data theft Tags: e-file Tags: tax Tags: Uber breach The most interesting security related news from the week of April 3 - 9. (Read more...) The post A week in security (April 3 - 9) appeared first on Malwarebytes Labs.
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
ChurchCRM version 4.5.1 suffers from a remote authenticated SQL injection vulnerability.
NotrinosERP version 0.7 suffers from a remote authentication blind SQL injection vulnerability.
Roxy Fileman versions 1.4.5 and below for .NET suffer from a remote shell upload vulnerability.
The Microsoft Windows kernel suffers from multiple issues with subkeys of transactionally renamed registry keys.
Goanywhere Encryption Helper version 7.1.1 suffers from a remote code execution vulnerability.
WebsiteBaker version 2.13.3 suffers from a cross site scripting vulnerability.
ESET Service version 16.0.26.0 suffers from an unquoted service path vulnerability.
dotclear version 2.25.3 suffers from a remote shell upload vulnerability.