Imperva Red Team Discovers Vulnerability in TikTok That Can Reveal User Activity and Information

## **TL;DR** The Imperva Red Team discovered a vulnerability in TikTok, a popular social media platform with more than one billion users worldwide, that could allow attackers to monitor users' activit ...

Continue Reading
Amazon Linux 2 : thunderbird (ALAS-2023-2028)

The version of thunderbird installed on the remote host is prior to 102.10.0-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2023-2028 advisory. - Ribose RNP bef ...

Continue Reading
Amazon Linux 2 : tomcat (ALAS-2023-2020)

The version of tomcat installed on the remote host is prior to 7.0.76-10. It is, therefore, affected by a vulnerability as referenced in the ALAS2-2023-2020 advisory. - When using the RemoteIpFilter ...

Continue Reading

CVSS3 - MEDIUM

MilleGPG5 5.9.2 (Gennaio 2023) – Local Privilege Escalation / Incorrect Access Control

Post ContentRead More ...

Continue Reading
MilleGPG5 5.9.2 (Gennaio 2023) – Local Privilege Escalation / Incorrect Access Control Vulnerability

Post ContentRead More ...

Continue Reading
Important: tomcat

**Issue Overview:** When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat ...

Continue Reading

CVSS3 - MEDIUM

Important: thunderbird

**Issue Overview:** The Mozilla Foundation describes this issue as follows: OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificat ...

Continue Reading
CVE-2023-29867

Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.Rea ...

Continue Reading

Back to Main

Subscribe for the latest news: