Skip to content

トピトピニュース

Header Image
Archive

Month: August 2022

402 Posts

Featured

Posted byUDiscoverMusic.
賭けに出たメガデスが驚くべき変貌を遂げたアルバム
Posted byテクノエッジ
Acer、裸眼3D立体視4Kモバイルモニタを一般向け発売。Unreal Engine やBlender の立体プレビュー対応
Posted byGame*Spark
海外レビューハイスコア『TMNT: The Cowabunga Collection』―レトロゲーム好きやタートルズファンにはたまらない一本
Posted byMagx-gw002
SCOOP!明日告知。日産リーフ、値上げへ

iPhone 14(仮) 純正シリコンケースの「クローン」、実績あるリーカーが公開

  • Posted inUncategorized
  • Posted byテクノエッジ
  • 08/19/2022

今年秋の「iPhone 14」シリーズは、「発表イベントが9月7日、9月16日に発売(いずれも米現地…

「iPhone 14」発表イベントは9月7日、発売は16日説が有力。新製品予想まとめ

  • Posted inUncategorized
  • Posted byテクノエッジ
  • 08/19/2022

「iPhone 14」シリーズが発表されるのは9月上旬というのは確実ながらも、「いつ発表されるか」に…

[getkirby/starterkit] Cross site scripting in getkirby/starterkit

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202208/31/2022

A stored cross-site scripting (XSS) vulnerability in Kirby’s Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-35174
h…

[AgileConfig.Client] Use of Hard-coded Credentials in AgileConfig.Client

  • Posted inCRITICAL
  • Posted byGitHub
  • 08/19/202208/31/2022

Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-35540
https://github.com/dotnetcore/AgileConfig/issues/91
ht…

[omniauth] OmniAuth’s `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value

  • Posted inCRITICAL
  • Posted byGitHub
  • 08/19/202209/20/2022

lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
References

https://nvd.nist.gov/vuln/detail/CVE-2020-36599
https://github.com/omniauth/omniauth/commit/43a396f181ef7d0ed2ec8291c939c95e3e…

[frontier] Incorrect parsing of EVM reversion exit reason in RPC

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202208/27/2022

Impact
A low severity security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release build, this would cause the exit reason being incorrectly parsed and returned by RPC. In debug build, this w…

[oqs] oqs’s Post-Quantum Signature scheme Rainbow level I parametersets broken

  • Posted inHIGH
  • Posted byGitHub
  • 08/19/202208/19/2022

Ward Beullens found a practical key-recovery attack against Rainbow.
The level I parametersets are removed from liboqs starting from version 0.7.2.
Find the scientific details in Breaking Rainbow Takes a Weekend on a Laptop.
This means all the oqs::sig…

[kubevirt.io/kubevirt] Duplicate Advisory: KubeVirt arbitrary host file read from the VM

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202209/30/2022

Duplicate Advisory
This advisory is a duplicate of GHSA-qv98-3369-g364. This link is maintained to preserve external references.
Original Description
Summary
As part of a Kubevirt audit performed by NCC group, a finding dealing with systemic lack of pa…

[oqs] oqs’s Post-Quantum Key Encapsulation Mechanism SIKE broken

  • Posted inMODERATE
  • Posted byGitHub
  • 08/19/202208/19/2022

Wouter Castryck and Thomas Decru presented an efficient key recovery attack on the SIDH protocol.
As a result, the secret key of SIKEp751 can be recovered in a matter of hours.
The SIKE and SIDH schemes will be removed from oqs 0.7.2.
An efficient key …

How the Chrome team uses Chrome

  • Posted inChrome
  • Posted bySamantha Martinez Hansen
  • 08/19/2022

Before Chrome browser was even launched, the Chrome team was working behind the scenes to create a different browsing experience: one that was both personalized and helpful. This mission has remained central to the Chrome team’s values as we continuous…

Posts navigation

Previous Posts 1 … 28 29 30 31 32 … 41 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close