Security
Headlines
HeadlinesLatestCVEs

Tag

#chrome

Prototype pollution bug in Chromium bypassed Sanitizer API

Issue highlights the challenges of preventing client-side attacks

PortSwigger
#vulnerability#web#nodejs#js#java#chrome
ChromeLoader Malware Evolves into Prevalent, More Dangerous Cyber Threat

Microsoft and VMware are warning that the malware, which first surfaced as a browser-hijacking credential stealer, is now being used to drop ransomware, steal data, and crash systems at enterprises.

Spell-Checking in Google Chrome, Microsoft Edge Browsers Leaks Passwords

It's called "spell-jacking": Both browsers have spell-check features that send data to Microsoft and Google when users fill out forms for websites or Web services.

CVE-2022-38545: A XSS bug that can execute code(用户恶意修改 评论 的ua可触发XSS执行代码) · Issue #400 · xCss/Valine

Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

Hookup site targeted by typo-squatters

Categories: News Tags: typosquatting Tags: sniffies Tags: extensions Tags: fake av Tags: screen locker Tags: advertising Tags: PUP.Optional.AdMax A researcher found a list of over 50 shady domains based on spelling variations of the brand name Sniffies. (Read more...) The post Hookup site targeted by typo-squatters appeared first on Malwarebytes Labs.

CVE-2022-40073: Vuln/Tenda AC21/5 at main · xxy1126/Vuln

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, saveParentControlInfo.

CVE-2022-40075: Vuln/Tenda AC21/1 at main · xxy1126/Vuln

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, form_fast_setting_wifi_set.

CVE-2022-40076: Vuln/Tenda AC21/4 at main · xxy1126/Vuln

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic.