Skip to main content

CND News and Blog

New Vulnerabilities Monday 05 September


New Alerts for Google Chrome, IBM, QNAP (Exploit), Veritas, and WithSecure.

Google 

Google has updated Chrome for Desktop with 1 security fix.
More info.

IBM 

IBM Business Process Manager and IBM Business Automation Workflow are vulnerable to a prototype pollution attack. CVSSv3 score of 9.8
More info.

QNAP - Exploit

QNAP detected a new DeadBolt ransomware campaign on the morning of September 3rd, 2022 (GMT+8). The campaign appears to target QNAP NAS devices running Photo Station with internet exposure.
More info. And here.

Veritas 

A Reflected XSS vulnerability affects the Desktop Laptop Option application login page. This allows remote attackers to inject arbitrary web script into the HTTP parameter which reflects the user input without sanitization due to Improper Neutralization of Input During Web Page Generation. CVSSv3 score of 6.1
More info.

WithSecure 

A DoS vulnerability was discovered in WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine. The exploit can be triggered remotely by an attacker.
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/