Cartoon Caption Winner: Greetings, Earthlings

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2021-22668
PUBLISHED: 2021-05-16

Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2021-29039
PUBLISHED: 2021-05-16

Cross-site scripting (XSS) vulnerability in the Asset module’s categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.

CVE-2020-16632
PUBLISHED: 2021-05-15

A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.

CVE-2021-32073
PUBLISHED: 2021-05-15

DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.

CVE-2021-33033
PUBLISHED: 2021-05-14

The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value.

Read More HERE

Leave a Reply