Security
Headlines
HeadlinesLatestCVEs

Tag

#ssl

The pitfalls of blocking IP addresses

Categories: News Tags: IP Tags: DNS Tags: IPv6 Tags: blocking Tags: domains Tags: Austria Tags: Cloudflare Tags: Freedom House Using IP blocks to make domains unreachable is a far-reaching method that has undesirable side effects because there is no one-on-one relationship. (Read more...) The post The pitfalls of blocking IP addresses appeared first on Malwarebytes Labs.

Malwarebytes
#vulnerability#web#ssl
CVE-2022-43382: Security Bulletin: AIX is vulnerable to a denial of service due to lpd (CVE-2022-43382)

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641.

What To Look For In The Best WordPress Hosting

By Owais Sultan Choosing the right hosting service provider is one of the most critical yet often overlooked components when it… This is a post from HackRead.com Read the original post: What To Look For In The Best WordPress Hosting

CVE-2022-44643: Downloads | Grafana Enterprise Metrics documentation

A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using this policy with the affected versions of the software. This issue affects: Grafana Labs Grafana Enterprise Metrics GEM 1.X versions prior to 1.7.1 on AMD64; GEM 2.X versions prior to 2.3.1 on AMD64.

CVE-2022-44643: Grafana Enterprise | Self-managed Prometheus service

In Grafana Enterprise Metrics (GEM) before 1.7.1 and 2.x before 2.3.1, after creating an Access Policy that is granted access to all tenants as well as specified a specific label matcher, the label matcher is erroneously not propagated to queries performed with this access policy. Thus, more access is granted to the policy than intended.

CVE-2022-40434: Build website, web app & portals on Airtable without code | Softr

Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.

Gentoo Linux Security Advisory 202212-05

Gentoo Linux Security Advisory 202212-5 - Multiple vulnerabilities have been discovered in NSS, the worst of which could result in arbitrary code execution. Versions less than 3.79.2 are affected.

CVE-2022-44456: Download License Agreement | CONTEC

CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.

4 over-hyped security vulnerabilities of 2022

Categories: Exploits and vulnerabilities Categories: News Tags: wormable Tags: zero-day Tags: spring4shell Tags: cve-2022-34718 Tags: log4j Tags: openssl Tags: cve-2022-36934 Tags: cve-2022-27492 Tags: cve-2022-22965 Tags: cve-2022-22963 What does it take to make the discussion of vulnerabilities useful? And where did this go wrong in 2022? (Read more...) The post 4 over-hyped security vulnerabilities of 2022 appeared first on Malwarebytes Labs.

CVE-2022-47210: NETGEAR Nighthawk WiFi6 Router Multiple Vulnerabilities

The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.