Exploit for Vulnerability in Microsoft

# CVE-2022-38023 Netlogon RPC Elevation of Privilege Vulnerabil...Read More ...

Continue Reading

CVSS3 - HIGH

RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided

## Description This is Samba's response to Microsoft's CVE-2022-38023[1][2]. Following RFC8429 and as has been published for CVE-2022-3938, rc4-hmac (also known as arcfour-hmac-md5) cryptography in Ke ...

Continue Reading

CVSS3 - HIGH

[SECURITY] Fedora 36 Update: capnproto-0.9.2-1.fc36

Cap=EF=BF=BD=EF=BF=BD=EF=BF=BDn Proto is an insanely fast data interchange format and capability-based RPC system. Think JSON, except binary. Or think Protocol Buffers, except faster. In fact, in ben ...

Continue Reading
[SECURITY] Fedora 37 Update: capnproto-0.9.2-1.fc37

Cap=EF=BF=BD=EF=BF=BD=EF=BF=BDn Proto is an insanely fast data interchange format and capability-based RPC system. Think JSON, except binary. Or think Protocol Buffers, except faster. In fact, in ben ...

Continue Reading
Quest NetVault Backup NVBUJobCountHistory SQL Injection (CVE-2017-17420)

An SQL injection vulnerability exists in the Server Process Manager Service of Quest NetVault Backup. The vulnerability is due to improper validation of user-supplied input on JSON-RPC requests invoki ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Security Bulletin: For IBM Cloudpak for Watson AIOPS 3.5.1

## Summary This SB contains a list for all CVE's listed here - CVE-2022-36083, CVE-2022-21123, CVE-2022-21125, CVE-2022-21166, CVE-2022-21797, CVE-2022-35941, CVE-2021-42248, CVE-2021-42836, CVE-2022- ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

8 KB is not enough: why WAFs can’t protect APIs

WAFs were a top-notch security instrument a decade ago, but now they are not. They fail to protect APIs. Meanwhile, the number of API-specific vulnerabilities grew more than twofold in 2022. According ...

Continue Reading
Reddit: Unrestricted File Upload on reddit.secure.force.com

## Summary: Reddit.secure.force.com is Reddit SalesForce instance. Attacker is able to send attachments of disallowed filetypes to this server. The attacker is able to send malicious documents such as ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: