#cve

calm.like.a.bombcalm_bomb@metalhead.club
2025-05-28

Fun fact! Janet Jackson is still the only pop star with a CVE to her credits.

The cybersecurity vulnerability is linked to her 1989 song "Rhythm Nation", which was found to crash certain models of laptops. The issue arose because the song contained a resonant frequency that matched the natural frequency of some 5400 RPM hard disk drives used in laptops around 2005. When played near these laptops, the song could cause the hard drive to malfunction, leading to a system crash. This unusual vulnerability was officially registered as CVE-2022-38392.

nvd.nist.gov/vuln/detail/CVE-2

#security #cve #funfact

NIST is now under federal audit for its management of the NVD, as delays and data gaps mount. Meanwhile, CISA faces major leadership losses & budget cuts. The #CVE Foundation has proposed a roadmap to fill the gap. Vulnerability infrastructure is at a turning point:

socket.dev/blog/us-government- #cybersecurity

Lambda Watchdoglambdawatchdog
2025-05-27

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 10 CVEs across 25 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 6
β€’ 🟑 Medium: 4
β€’ πŸ”΅ Low: 0

Check the full report πŸ‘‰ lambdawatchdog.com/

2025-05-27

#OT #Advisory VDE-2025-044
Weidmueller: Industrial ethernet switches are affected by multiple vulnerabilities

#CVE CVE-2025-41651, CVE-2025-41652, CVE-2025-41649, CVE-2025-41650, CVE-2025-41653

certvde.com/en/advisories/VDE-

#CSAF weidmueller.csaf-tp.certvde.co

2025-05-27

#OT #Advisory VDE-2025-042
Lenze: VPN Client Privilege Escalation in combination with Lenze x500 IoT Gateway

#CVE CVE-2025-26168, CVE-2025-26169

certvde.com/en/advisories/VDE-

#CSAF lenze.csaf-tp.certvde.com/.wel

Alexandre Dulaunoyadulau@infosec.exchange
2025-05-26

CVE-2024-4367 (PDF.js) is gaining traction in some exploitation-focused Telegram channels...

vulnerability.circl.lu/cve/CVE

seen via @ail_project

#vulnerability #opensource #threatintelligence #cve #exploit

CVE-2024-4367 (PDF.js) is gaining traction in some exploitation-focused Telegram channels... via AIL project.
Nicolas Mouartsilentexception
2025-05-26

ENISA launched the European Vulnerability Database (EUVD or EU Vulnerability Database), as mandated by the NIS2 Directive. There is the Cyber resilience act (CRA) incoming as well, on increasing the security standards on IoT products (like this one in the screenshot :/ )
euvd.enisa.europa.eu/vulnerabi

CVE-2025-2233 Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Hub Local API service, which listens on TCP port 8766 by default. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25615.
Lambda Watchdoglambdawatchdog
2025-05-26

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 10 CVEs across 25 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 6
β€’ 🟑 Medium: 4
β€’ πŸ”΅ Low: 0

Check the full report πŸ‘‰ lambdawatchdog.com/

2025-05-26

#OT #Advisory VDE-2025-011
PEPPERL+FUCHS: Profinet Gateway LB8122A.1.EL – Device is affected by XSS vulnerability and information disclosure

#CVE CVE-2025-41654, CVE-2025-41655, CVE-2025-1985

certvde.com/en/advisories/VDE-

#CSAF pepperl-fuchs.csaf-tp.certvde.

Sentinel SecuritySntlSecurity
2025-05-26

Log4j taught us: your software supply chain is a bomb with a long fuse.
You don’t notice it until it explodes.
πŸ’₯ Know your components.
πŸ’£ Validate your inputs.

Lambda Watchdoglambdawatchdog
2025-05-25

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 10 CVEs across 25 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 6
β€’ 🟑 Medium: 4
β€’ πŸ”΅ Low: 0

Check the full report πŸ‘‰ lambdawatchdog.com/

Lambda Watchdoglambdawatchdog
2025-05-24

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 10 CVEs across 25 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 6
β€’ 🟑 Medium: 4
β€’ πŸ”΅ Low: 0

Check the full report πŸ‘‰ lambdawatchdog.com/

Lambda Watchdoglambdawatchdog
2025-05-23

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 10 CVEs across 25 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 6
β€’ 🟑 Medium: 4
β€’ πŸ”΅ Low: 0

Check the full report πŸ‘‰ lambdawatchdog.com/

2025-05-23

apt-listchanges: News
---------------------

#glibc (2.41-7) unstable; urgency=medium

Starting with glibc 2.41, shared libraries requiring an executable stack
cannot be dynamically loaded through the dlopen mechanism from a binary that
does not require an executable stack. This change aims to improve #security,
as the previous behavior was used as a vector for RCE (#CVE-2023-38408).
Attempting to do so will result in the following error:

cannot enable executable stack as shared object requires: Invalid argument

While most libraries generated in the past 20 years do not require an
executable stack, some third-party software still need this capability. Many
vendors have already updated their binaries to address this.

If you need to run a program that requires an executable stack through
dynamic loaded shared libraries, you can use the glibc.rtld.execstack
tunable:

GLIBC_TUNABLES=glibc.rtld.execstack=2 ./program

-- Aurelien Jarno <aurel32@debian.org> Sun, 13 Apr 2025 14:41:11 +0200

#Debian #Trixie #Linux

BΓ‘lint Magyarbalint
2025-05-22

Just posted my new article on another client-side remote code execution bug I found in Google Web Designer back in February, tracked as CVE-2025-4613, fixed in an April release. Enjoy the write-up!

bm.gy/gwdrce2

st1nger :unverified: πŸ΄β€β˜ οΈ :linux: :freebsd:st1nger@infosec.exchange
2025-05-22
CVE ProgramCVE_Program
2025-05-22

1,110 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of May 12, 2025

cisa.gov/news-events/bulletins

Lambda Watchdoglambdawatchdog
2025-05-22

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 10 CVEs across 25 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 6
β€’ 🟑 Medium: 4
β€’ πŸ”΅ Low: 0

Check the full report πŸ‘‰ lambdawatchdog.com/

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst