Tag
Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
The U.S. Federal Bureau of Investigation (FBI) is warning that Barracuda Networks Email Security Gateway (ESG) appliances patched against a recently disclosed critical flaw continue to be at risk of potential compromise from suspected Chinese hacking groups. It also deemed the fixes as "ineffective" and that it "continues to observe active intrusions and considers all affected Barracuda ESG
AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.
By Deeba Ahmed The new Whiffy Recon Malware was identified by cybersecurity researchers at Secureworks. This is a post from HackRead.com Read the original post: Smoke Loader Botnet Drops Location Tracker Whiffy Recon Malware
The latest activity from Lazarus Groups, .gov domains scamming people out of "V-Bucks" and more in this week's edition.
GEN Security+ version 4.0 suffers from a cross site scripting vulnerability.
Geeklog version 2.1.0b1 suffers from a remote SQL injection vulnerability.
GraceHRM version 1.0.3 suffers from a directory traversal vulnerability.
User Registration and Login and User Management System version 3.0 suffers from a persistent cross site scripting vulnerability.
User Registration and Login and User Management System version 3.0 suffers from a remote SQL injection vulnerability.