CVE-2022-41035
Microsoft Edge (Chromium-based) Spoofing Vulnerability.Read More ...
Continue ReadingOctober 11, 2022
CVE-2022-41035
Microsoft Edge (Chromium-based) Spoofing Vulnerability.Read More ...
Continue ReadingOctober 11, 2022
CVE-2022-41081
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22035, CVE-2022-24504, CVE-2022-30198, CVE-2022-33634, CVE-2022-38000, CVE-2022-38047 ...
Continue ReadingOctober 11, 2022
CVE-2022-41036
Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41037, CVE-2022-41038.Read More ...
Continue ReadingOctober 11, 2022
CVE-2022-41037
Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41036, CVE-2022-41038.Read More ...
Continue ReadingOctober 11, 2022
CVE-2022-41038
Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41036, CVE-2022-41037.Read More ...
Continue ReadingOctober 11, 2022
CVE-2022-41042
Visual Studio Code Information Disclosure Vulnerability.Read More ...
Continue ReadingOctober 11, 2022
CVE-2022-41083
Visual Studio Code Elevation of Privilege Vulnerability.Read More ...
Continue ReadingOctober 11, 2022
Weak Password Requirements
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess o ...
Continue ReadingOctober 10, 2022
Hyperledger: Remote denial of service in HyperLedger Fabric
How to reproduce 1.Bring up the test network.(https://hyperledger-fabric.readthedocs.io/en/latest/test_network.html#bring-up-the-test-network) 2.Run the PoC. ```bash go run poc.go -server=192.168.0.20 ...
Continue ReadingOctober 10, 2022
Reddit: Unrestricted File Upload on reddit.secure.force.com
## Summary: Reddit.secure.force.com is Reddit SalesForce instance. Attacker is able to send attachments of disallowed filetypes to this server. The attacker is able to send malicious documents such as ...
Continue ReadingOctober 10, 2022