Zoom Announces Rollout of End-to-End Encryption

Zoom Announces Rollout of End-to-End Encryption
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2020-7383PUBLISHED: 2020-10-14

A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access resources & make changes they should not have been able to access.

CVE-2020-3483PUBLISHED: 2020-10-14

Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys were not excluded from logging. This issue resulted in certificate and private key information being written out in plain-text to local files on the DNG ...

CVE-2020-7317PUBLISHED: 2020-10-14

Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.

CVE-2020-7318PUBLISHED: 2020-10-14

Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.

CVE-2020-15224PUBLISHED: 2020-10-14

In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a malicious host application. An attacker who successfully ..

Support the originator by clicking the read the rest link below.