Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2022-36605: ywoa SQL inject Bypass and Analysis of the article · Issue #24 · cloudwebsoft/ywoa

Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.

CVE
#sql#xss#vulnerability#web#mac#windows#js#java#intel#c++#auth#firefox
DoNot Team Hackers Updated its Malware Toolkit with Improved Capabilities

The Donot Team threat actor has updated its Jaca Windows malware toolkit with improved capabilities, including a revamped stealer module designed to plunder information from Google Chrome and Mozilla Firefox browsers. The improvements also include a new infection chain that incorporates previously undocumented components to the modular framework, Morphisec researchers Hido Cohen and Arnold

CVE-2022-36220: Kiosk escape (vulnerability disclosure) · Issue #434 · SafeExamBrowser/seb-win-refactoring

Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.

CVE-2022-2075: Security Advisory 2022-12

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.

CVE-2022-2074: Security Advisory 2022-11

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.

CVE-2022-2049: Security Advisory 2022-10

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function.

CVE-2022-1901: Security Advisory 2022-09

In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.

CVE-2022-35167

Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.

Spyware Hunters Are Expanding Their Toolset

This invasive malware isn’t just for phones—it can target your PC, too. But a new batch of algorithms aims to weed out this threat.