Security
Headlines
HeadlinesLatestCVEs

Tag

#android

CVE-2022-35221: 互動資通 Teamplus Pro - Allocation of Resources Without Limits or Throttling-2

Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attacker with general user privilege posting a thread subject with large content can cause the server to allocate too much memory, leading to missing partial post content and disrupt partial service.

CVE
#vulnerability#ios#android
CVE-2022-35220: 互動資通 Teamplus Pro - Allocation of Resources Without Limits or Throttling-1

Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A remote attacker with general user privilege posting a thread with large content can cause the receiving client device to allocate too much memory, leading to abnormal termination of this client’s Teamplus Pro application.

Incognia Mobile App Study Reveals Low Detection of Location Spoofing in Dating Apps

With over 323 million users of dating apps worldwide, study finds location spoofing is a threat to user trust and safety.

New DawDropper Malware Targeting Android Devices via Play Store

By Waqas According to Trend Micro researchers, the DawDropper aims at stealing user data, in particular from banking apps on… This is a post from HackRead.com Read the original post: New DawDropper Malware Targeting Android Devices via Play Store

Vulnerability Spotlight: How misusing properly serialized data opened TCL LinkHub Mesh Wi-Fi system to 17 vulnerabilities

By Carl Hurd.  The TCL LinkHub Mesh Wi-Fi system is a multi-device Wi-Fi system that allows users to expand access to their network over a large physical area. What makes the LInkHub system unique is the lack of a network interface to manage the devices individually or in the mesh. Instead, a phone application is the only method to interact with these devices. This is noteworthy because, in theory, it significantly reduces the common attack surface on most small office/home office (SOHO) routers, as it moves the entire HTTP/S code base from the product. This means, in theory, fewer issues with integration or hacked-together scripts to trigger various functions within the device. One of the issues with this approach though is that its functionality still needs to reside somewhere for the user to manage the device.  However, this setup leaves the LinkHub Mesh Wi-Fi system open to several vulnerabilities, which we are disclosing today. An attacker could exploit these vulnerabilities to ...

Aussie Hacker Arrested, Charged for Developing and Selling Imminent Monitor RAT

By Deeba Ahmed The Australian police arrested an Australian hacker for creating and selling the extensively abused Imminent Monitor RAT (remote… This is a post from HackRead.com Read the original post: Aussie Hacker Arrested, Charged for Developing and Selling Imminent Monitor RAT

CVE-2022-21788: August 2022

In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06988728; Issue ID: ALPS06988728.

You Need a Password Manager. Here Are the Best Ones

Keep your logins locked down with our favorite apps for PC, Mac, Android, iPhone, and web browsers.

A week in security (July 25 - July 31)

Categories: A week in security Tags: backdoor Tags: blog recap Tags: bytedance Tags: cookies Tags: data breach Tags: Google Tags: linux Tags: microsoft Tags: ransomware Tags: SQL injection Tags: T-Mobile Tags: tiktok Tags: Uber Tags: week in security The most important and interesting computer security stories from the last week. (Read more...) The post A week in security (July 25 - July 31) appeared first on Malwarebytes Labs.