NSA Recommends Using Only 'Designated' DNS Resolvers

NSA Recommends Using Only 'Designated' DNS Resolvers
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2021-22132PUBLISHED: 2021-01-14

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in th...

CVE-2021-21261PUBLISHED: 2021-01-14

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versi...

CVE-2021-21722PUBLISHED: 2021-01-14

A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers could use this vulnerability to obtain sensitive user information for further information detection and attacks. This affects: ZXV10 B860A V2.1-T_V0032.1.1.04_jiangsuTelecom.

CVE-2020-29016PUBLISHED: 2021-01-14

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.

CVE-2020-29017PUBLISHED: 2021-01-14

An OS command injection vulnerability ..

Support the originator by clicking the read the rest link below.