T-Mobile confirms it was hacked in the wave of recently reported telecom breaches conducted by Chinese threat actors to gain access to private communications, call records, and law enforcement information requests. [...]
Palo Alto Networks confirmed active exploitation of a zero-day in its PAN-OS firewall and released new indicators of compromise (IoCs). Last week, Palo Alto Networks warned customers to limit access to their next-gen firewall management interface due to a potential remote code execution vulnerability (CVSSv4.0 Base Score: 9.3) in PAN-OS. The cybersecurity company had no […]
A vulnerability was found in Openscad and classified as critical. Affected by this issue is the function import of the component DXF Format Handler. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2022-0496. The attack needs to be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Smarty up to 3.1.38. It has been declared as critical. This vulnerability affects unknown code of the component Function Handler. The manipulation leads to code injection.
This vulnerability was named CVE-2021-26120. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Samba. Affected is the function gnutls_rnd of the file lib/util/genrand.c of the component GnuTLS. The manipulation leads to insufficiently random values.
This vulnerability is traded as CVE-2022-1615. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic was found in FreeRDP up to 2.8.0. This vulnerability affects unknown code of the component parallel Command Handler. The manipulation leads to uninitialized resource.
This vulnerability was named CVE-2022-39282. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in FreeRDP up to 2.8.0. This issue affects some unknown processing of the component video Command Handler. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2022-39283. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Smarty up to 3.1.38. It has been classified as critical. This affects the function $smarty.template_object of the component Sandbox Mode. The manipulation leads to sandbox issue.
This vulnerability is uniquely identified as CVE-2021-26119. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Smarty up to 3.1.42/4.0.2. This affects an unknown part of the component Template Handler. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2021-21408. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Smarty up to 3.1.44/4.1.0. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2022-29221. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in cmark-gfm up to 0.29.0.gfm.5. It has been classified as problematic. This affects an unknown part of the component Autolink Extension. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2022-39209. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.