Search found 1729 matches

by Shane1145
Thu Oct 23, 2025 12:02 pm
Forum: Mobile Phones
Topic: Denial of Service Vulnerability in Samsung Mobile and Wearable Processors
Replies: 0
Views: 95

Denial of Service Vulnerability in Samsung Mobile and Wearable Processors

A vulnerability has been identified in Samsung's Mobile and Wearable Processors, specifically within the Exynos series. The flaw arises from a lack of NULL checks, enabling attackers to exploit this weakness through the transmission of malformed MM packets. This exploitation results in a Denial of ...
by Shane1145
Thu Oct 23, 2025 12:01 pm
Forum: Android/iOS
Topic: Memory Management Vulnerability in Apple Operating Systems
Replies: 0
Views: 87

Memory Management Vulnerability in Apple Operating Systems

A memory management vulnerability has been identified across various Apple operating systems, including macOS, iOS, and more. This issue arises from a double free error, which can lead to unexpected system termination when exploited by malicious applications. To address this flaw, Apple has released ...
by Shane1145
Thu Oct 23, 2025 12:00 pm
Forum: macOS
Topic: Logic Issue in macOS Products by Apple
Replies: 0
Views: 67

Logic Issue in macOS Products by Apple

A logic issue present in certain versions of macOS has been found to potentially allow applications to access sensitive user information without proper authorization. This vulnerability has been addressed with improved restrictions in the latest updates for macOS Ventura, Sonoma, and Sequoia ...
by Shane1145
Thu Oct 23, 2025 11:57 am
Forum: Programming Languages
Topic: Unbounded DEFLATE Decompression Vulnerability in Authlib Python Library
Replies: 0
Views: 66

Unbounded DEFLATE Decompression Vulnerability in Authlib Python Library

Authlib, a Python library utilized for building OAuth and OpenID Connect servers, has a significant vulnerability associated with its handling of JWE tokens. Specifically, prior to version 1.6.5, the library's implementation allows for unbounded DEFLATE decompression when the zip=DEF parameter is ...
by Shane1145
Wed Oct 22, 2025 3:10 pm
Forum: Commercial
Topic: LANSCOPE Endpoint Manager Vulnerability Allows Attackers to Execute Remote Code
Replies: 0
Views: 91

LANSCOPE Endpoint Manager Vulnerability Allows Attackers to Execute Remote Code

A critical remote code execution vulnerability has been discovered in the on-premise edition of LANSCOPE Endpoint Manager that allows unauthenticated attackers to run arbitrary commands with high privileges on affected systems.

Tracked as CVE-2025-61932, the flaw impacts both the Client Program (MR ...
by Shane1145
Wed Oct 22, 2025 3:06 pm
Forum: Commercial
Topic: Microsoft 365 Copilot Flaw Lets Hackers Steal Sensitive Data via Indirect Prompt Injection
Replies: 0
Views: 122

Microsoft 365 Copilot Flaw Lets Hackers Steal Sensitive Data via Indirect Prompt Injection

A vulnerability in Microsoft 365 Copilot allowed attackers to trick the AI assistant into fetching and exfiltrating sensitive tenant data by hiding instructions in a document.

The AI then encoded the data into a malicious Mermaid diagram that, when clicked, sent the stolen information to an ...
by Shane1145
Tue Oct 21, 2025 6:12 am
Forum: IOT Devices
Topic: Remote Command Injection Vulnerability in GeoVision IP Devices
Replies: 0
Views: 183

Remote Command Injection Vulnerability in GeoVision IP Devices

GeoVision embedded IP devices, specifically the GV-BX1500 and GV-MFD1501 models, are susceptible to a remote command injection flaw via the/PictureCatch.cgi endpoint. This vulnerability allows attackers to execute arbitrary commands on the affected devices remotely. Observations indicate that this ...
by Shane1145
Tue Oct 21, 2025 5:59 am
Forum: Commercial
Topic: Critical Veeam Backup Flaws Allow Remote Code Execution
Replies: 0
Views: 128

Critical Veeam Backup Flaws Allow Remote Code Execution

Veeam has released Patch 12.3.2.4165 for Backup & Replication, resolving three significant security flaws that could expose organizations to remote code execution and privilege escalation risks.

Published on October 14, 2025, the update addresses two critical CVE-2025-48983 and CVE-2025-48984 ...
by Shane1145
Tue Oct 21, 2025 5:57 am
Forum: Desktop Applications
Topic: Chrome ‘Use-After-Free’ Flaw Enables Arbitrary Code Execution
Replies: 0
Views: 140

Chrome ‘Use-After-Free’ Flaw Enables Arbitrary Code Execution

Google has begun rolling out the latest Stable channel update for Chrome desktop users, advancing the browser to version 141.0.7390[.]107/.108 on Windows and macOS, and 141.0.7390[.]107 on Linux.

This release, announced on October 14, 2025, introduces performance refinements and bug fixes, but its ...
by Shane1145
Tue Oct 21, 2025 5:56 am
Forum: Web Applications
Topic: Critical Apache ActiveMQ Flaw Enables Remote Code Execution
Replies: 0
Views: 103

Critical Apache ActiveMQ Flaw Enables Remote Code Execution

A newly disclosed vulnerability in the Apache ActiveMQ NMS AMQP Client has sent shockwaves through the messaging middleware community.

Tracked as CVE-2025-54539, this deserialization of untrusted data flaw carries an important severity rating and can allow malicious AMQP servers to execute ...