Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2022-34336: IBM WebSphere Application Server is vulnerable to cross-site scripting in the Admin Console (CVE-2022-34336)

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.

CVE
#xss#vulnerability#web#windows#linux#java#ibm
CVE-2022-37703: Open Source Backup for Linux, Windows, UNIX and OS X

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

ShadowPad Threat Actors Return With Fresh Government Strikes, Updated Tools

Cyber spies are using legitimate apps for DLL sideloading, deploying an updated range of malware, including the new "Logdatter" info-stealer.

CVE-2022-37964

Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37956, CVE-2022-37957.

CVE-2022-34724

Windows DNS Server Denial of Service Vulnerability.

CVE-2022-34723

Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability.

CVE-2022-33679

Windows Kerberos Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-33647.

CVE-2022-33647

Windows Kerberos Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-33679.

CVE-2022-30196

Windows Secure Channel Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-35833.

CVE-2022-34725

Windows ALPC Elevation of Privilege Vulnerability.