Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

NullMixer Polymorphic Malware Variant Infects 8K Targets in Just a Month

The NullMixer loader has compromised thousands of endpoints in the US, France, and Italy, stealing data and selling it to Dark Web data dealers, all without setting off alarm bells.

DARKReading
#vulnerability#web#windows
Hey, Siri: Hackers Can Control Smart Devices Using Inaudible Sounds

A technique, dubbed the "Near-Ultrasound Inaudible Trojan" (NUIT), allows an attacker to exploit smartphones and smart speakers over the Internet, using sounds undetectable by humans.

SolarWinds Information Service (SWIS) Remote Command Execution

The SolarWinds Information Service (SWIS) is vulnerable to remote code execution by way of a crafted message received through the AMQP message queue. A malicious user that can authenticate to the AMQP service can publish such a crafted message whose body is a serialized .NET object which can lead to OS command execution as NT AUTHORITY\SYSTEM.

CVE-2023-26923: [MU4 Issue] Stack buffer overflow vulnerability while parse MIDI file · Issue #16346 · musescore/MuseScore

Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.

Moodle LMS 4.0 Cross Site Scripting

Moodle LMS version 4.0 suffers from a cross site scripting vulnerability.

Tunnel Interface Driver Denial Of Service

Tunnel Interface Driver suffers from a denial of service vulnerability.

OPSWAT Metadefender Core 4.21.1 Privilege Escalation

OPSWAT Metadefender Core version 4.21.1 suffers from a privilege escalation vulnerability.

X-Skipper-Proxy 0.13.237 Server-Side Request Forgery

X-Skipper-Proxy version 0.13.237 suffers from a server-side request forgery vulnerability.