Snapshot
Nov. 25, 2023 - Dec. 1, 2023
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2023-49103 | ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials. | CRITICAL | ownCloud | Nov. 30, 2023 |
CVE-2023-6345 | Google Skia contains an integer overflow vulnerability affecting Google Chrome and ChromeOS, Android, Flutter, and possibly other products. | N/A | Nov. 30, 2023 | |
Newswires |
||||
CISA Catalogs Exploited Vulnerabilities in ownCloud and Google Chrome
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities catalog, adding vulnerabilities found in ownCloud and Google Chrome. |
Dec. 1, 2023 |
|||
Apple Rushes to Patch Two Zero-Day Vulnerabilities in Emergency Updates
Apple has rushed out emergency security patches to rectify two zero-day vulnerabilities that have been exploited in attacks. |
Nov. 30, 2023 |
|||
Cactus Ransomware Targets Qlik Sense Vulnerabilities to Infiltrate Networks
The Cactus ransomware has reportedly been exploiting significant vulnerabilities in the Qlik Sense data analytics tool to gain initial foothold in corporate networks. |
Nov. 30, 2023 |
|||
Rhysida Ransomware Group Targets King Edward VII’s Hospital in London
The Rhysida ransomware group has reportedly breached the security of King Edward VII’s Hospital, a prominent private healthcare provider in central London, and has stolen a significant amount of sensitive data. |
Nov. 30, 2023 |
|||
BLUFFS Bluetooth Attacks Pose Major Threat: A Researcher's Study
Daniele Antonioli, an assistant professor at EURECOM, has unveiled a series of new attacks that compromise the forward and future secrecy of Bluetooth sessions. |
Nov. 29, 2023 |
|||
Unpatched Vulnerabilities Detected in Ray Open Source Framework for AI/ML
The Ray open source framework, used by organizations to scale artificial intelligence and machine learning workloads, has been found to have three unpatched vulnerabilities, potentially exposing users to attacks. |
Nov. 28, 2023 |
|||
Google Chrome Rolls Out Urgent Security Update to Address 6th Zero-Day Exploit in 2023
Google has released an emergency security update to address the sixth zero-day vulnerability discovered in Chrome this year. |
Nov. 28, 2023 |
|||
Critical ownCloud Vulnerability Under Active Exploitation
Threat actors have initiated the exploitation of a critical vulnerability in the open-source file-sharing and collaboration platform ownCloud. |
Nov. 28, 2023 |
|||
North Korean Hackers Innovate macOS Malware Tactics to Elude Detection
North Korean cyber adversaries behind macOS malware variants such as RustBucket and KANDYKORN have been seen to 'mix and match' distinct elements of the two different attack chains. |
Nov. 28, 2023 |
|||
General Electric and DARPA Data Breach Raises National Security Questions
Allegations of a cyber breach involving General Electric (GE) and the Defense Advanced Research Projects Agency (DARPA) have emerged, with the possibility of highly sensitive data being sold on the Dark Web. |
Nov. 27, 2023 |
|||
Healthcare Behemoth Henry Schein Targeted Twice by BlackCat Ransomware
Henry Schein, an American healthcare company and a Fortune 500 entity, has been hit twice within a month by the BlackCat/ALPHV ransomware gang. |
Nov. 27, 2023 |
|||
Rhysida Ransomware Group Claims Attack on China Energy Engineering Corporation
The Rhysida ransomware group has announced a cyberattack on the China Energy Engineering Corporation (CEEC), a prominent state-owned energy company in China. |
Nov. 25, 2023 |
|||
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2023-49103 (8) | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. | CRITICAL | Owncloud |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2023-49105 (6) | An issue was discovered in ownCloud owncloud/core before 10.13.1. | CRITICAL | Owncloud | Risk Context N/A |
CVE-2023-46604 (5) | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. | CRITICAL | Apache |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
CVE-2023-5217 (6) | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote at... | HIGH | Google, Webmproject, Fedoraproject, Mozilla, Apple, Microsoft, Debian |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2023-4863 (5) | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perfo... | HIGH | Google, Webmproject, Fedoraproject, Mozilla, Microsoft, Debian |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2023-49104 (5) | An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. | MEDIUM | Owncloud | Risk Context N/A |
CVE-2023-6345 (14) | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer ... | N/A |
CISA Known Exploited Actively Exploited Remote Code Execution |
|
CVE-2023-42917 (9) | A memory corruption vulnerability was addressed with improved locking. | N/A | Risk Context N/A | |
CVE-2023-42916 (9) | An out-of-bounds read was addressed with improved input validation. | N/A | Risk Context N/A | |
CVE-2023-24023 (4) | Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 throug... | N/A |
Actively Exploited Remote Code Execution |
CISA Known Exploited Vulnerabilities
CISA added two vulnerabilities to the known exploited vulnerabilities list.
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2023-49103 |
CRITICAL CVSS 10.00 EPSS Score 10.89 EPSS Percentile 94.52 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Nov. 21, 2023 |
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure. |
Vendor Impacted: Owncloud |
Product Impacted: Owncloud Graphapi |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-49105 |
CRITICAL CVSS 9.80 EPSS Score 0.09 EPSS Percentile 38.23 |
Risk Context N/A |
Published: Nov. 21, 2023 |
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0. |
Vendor Impacted: Owncloud |
Product Impacted: Owncloud |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-46604 |
CRITICAL CVSS 9.80 EPSS Score 96.81 EPSS Percentile 99.60 |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
Published: Oct. 27, 2023 |
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue. |
Vendor Impacted: Apache |
Products Impacted: Activemq Legacy Openwire Module, Activemq |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-5217 |
HIGH CVSS 8.80 EPSS Score 22.99 EPSS Percentile 96.04 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Sept. 28, 2023 |
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Vendors Impacted: Google, Webmproject, Fedoraproject, Mozilla, Apple, Microsoft, Debian |
Products Impacted: Firefox Focus, Firefox Esr, Chrome, Edge Chromium, Libvpx, Chrome Libvpx, Firefox, Debian Linux, Ipad Os, Iphone Os, Fedora, Edge |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-4863 |
HIGH CVSS 8.80 EPSS Score 41.01 EPSS Percentile 96.92 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Sept. 12, 2023 |
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) |
Vendors Impacted: Google, Webmproject, Fedoraproject, Mozilla, Microsoft, Debian |
Products Impacted: Firefox Esr, Chrome, Chromium Webp, Libwebp, Thunderbird, Firefox, Debian Linux, Fedora, Edge |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-49104 |
MEDIUM CVSS 6.10 EPSS Score 0.04 EPSS Percentile 6.93 |
Risk Context N/A |
Published: Nov. 21, 2023 |
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker. |
Vendor Impacted: Owncloud |
Product Impacted: Oauth2 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-42917 |
CVSS Not Assigned EPSS Score 0.07 EPSS Percentile 27.16 |
Risk Context N/A |
Published: Nov. 30, 2023 |
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-42916 |
CVSS Not Assigned EPSS Score 0.07 EPSS Percentile 29.13 |
Risk Context N/A |
Published: Nov. 30, 2023 |
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-24023 |
CVSS Not Assigned EPSS Score 0.04 EPSS Percentile 6.93 |
Actively Exploited Remote Code Execution |
Published: Nov. 28, 2023 |
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS. |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.