Tag
#webkit
WBCE CMS version 1.6.1 suffers from a cross site scripting vulnerability.
Steam, the most popular video game storefront on PCs, only recently announced that it was ending support for Windows 7 and 8, and even then, it won’t be official until January.
2023 Online Course Registration version 1.0 suffers from a remote SQL Injection vulnerability that allows for authentication bypass.
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
thrsrossi Millhouse-Project version 1.414 suffers from a remote shell upload vulnerability.
Quicklancer version 1.0 suffers from a remote SQL injection vulnerability.
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
Categories: Exploits and vulnerabilities Categories: News Tags: Apple Tags: RSR Tags: CVE-2023-32409 Tags: CVE-2023-28204 Tags: CVE-2023-32373 Tags: out of bounds Tags: use after free Apple issued information about patches against three actively exploited zero-days in WebKit. One vulnerability is new, two were patched earlier this month. (Read more...) The post Update now! Apple issues patches for three actively used zero-days appeared first on Malwarebytes Labs.
In an advisory released by the company, Apple revealed patches for three previously unknown bugs it says may already have been used by attackers.