Aggregator
Learning from the NASCIO Annual Conference 2024
The National Association of State CIOs (NASCIO) held its annual conference in New Orleans, La., this past week. Here are some of the highlights, along with some thoughts about what the future holds for state CIOs.
The post Learning from the NASCIO Annual Conference 2024 appeared first on Security Boulevard.
Weekly Update 420
CVE-2016-3944 | Lenovo Accelerator Application UserAgent input validation (ID 370006)
CVE-2007-4809 | Online Fantasy Football League lib/functions.php DOC_ROOT code injection (EDB-4374 / XFDB-36529)
CVE-2016-3958 | Google Go up to 1.5.3/1.6.0 on Windows LoadLibrary access control (ID 14959 / ID 370002)
CVE-2016-3977 | giflib 5.1.2 GIF Image util/gif2rgb.c memory corruption (ea8dbc57 / Nessus ID 90756)
爱奇艺暂停后播放全屏广告引热议;闪送登陆纳斯达克;SHEIN 创始人许仰天将赴美会见投资者 | 极客早知道
CVE-2000-0844 | Unix 6.2 Locale Subsystem gettext/catopen access control (EDB-197 / XFDB-5176)
CVE-2007-4809 | Online Fantasy Football League OFFL 0.2.3/0.2.6 lib/header.php DOC_ROOT code injection (EDB-4374 / XFDB-36529)
Google Pixel 9 supports new security features to mitigate baseband attacks
CVE-2016-3992 | cronic prior 3 cronic.trace.$$ access control (Nessus ID 91952 / ID 168958)
CVE-2024-41708 | AdaCore ada_web_services 20.0 src/core/aws-utils.adb Random_String random values (Nessus ID 208221)
CVE-2014-7430 | Flood-It 4.2 X.509 Certificate cryptographic issues (VU#582497)
CVE-2016-4000 | Oracle Rapid Planning 12.1/12.2 Middle Tier deserialization (ID 176072)
CVE-2007-4821 | EDraw Office Viewer Component 5.2 ActiveX Control officeviewer.ocx first memory corruption (EDB-4373 / Nessus ID 26198)
Week in review: Critical Zimbra RCE vulnerability exploited, Patch Tuesday forecast
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: October 2024 Patch Tuesday forecast: Recall can be recalled October arrived, and Microsoft started the month by announcing the release of Windows 11 24H2. The preview versions of this release have been in the news due to many innovations and one controversial feature. Critical Zimbra RCE vulnerability under mass exploitation (CVE-2024-45519) Attackers are actively exploiting CVE-2024-45519, a critical Zimbra vulnerability … More →
The post Week in review: Critical Zimbra RCE vulnerability exploited, Patch Tuesday forecast appeared first on Help Net Security.