Apple has released iOS and iPadOS updates to address two security issues, one of which could have allowed a user's passwords to be read out aloud by its VoiceOver assistive technology.
The vulnerability, tracked as CVE-2024-44204, has been described as a logic problem in the new Passwords app impacting a slew of iPhones and iPads. Security researcher Bistrit Daha has been credited with
A vulnerability classified as problematic has been found in HP LaserJet Printer. This affects an unknown part of the component Raw JPEG File Handler. The manipulation leads to improper handling of unexpected data type.
This vulnerability is uniquely identified as CVE-2024-9423. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in OpenText Vertica 10.x/11.x/12.x/23.x/24.x. This vulnerability affects unknown code. The manipulation leads to incorrect permission assignment.
This vulnerability was named CVE-2024-6360. It is possible to launch the attack on the local host. There is no exploit available.
A vulnerability, which was classified as critical, was found in Cisco Nexus Dashboard Orchestrator. This affects an unknown part of the component NDO Validate Peer Certificate Site Management. The manipulation leads to improper certificate validation.
This vulnerability is uniquely identified as CVE-2024-20385. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Cisco RV340, RV340W, RV345 and RV345P. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2024-20393. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Cisco Nexus Dashboard Fabric Controller up to 12.2.1 and classified as critical. This vulnerability affects unknown code of the component REST API/Web UI. The manipulation leads to command injection.
This vulnerability was named CVE-2024-20432. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Cisco Nexus Dashboard Fabric Controller up to 12.2.1 and classified as critical. This issue affects some unknown processing of the component REST API Endpoint. The manipulation leads to protection mechanism failure.
The identification of this vulnerability is CVE-2024-20438. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in SpeedTech PHP Library and classified as critical. This issue affects some unknown processing in the library STPHPLIB_DIR of the file stphprichbutton.php. The manipulation of the argument STPHPLIB_DIR leads to code injection.
The identification of this vulnerability is CVE-2007-4737. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in buronya Dil Bilgisi Kurallari 1. It has been classified as critical. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-7398. Access to the local network is required for this attack. There is no exploit available.