Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-31099PUBLISHED: 2022-06-27
rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, the stack may overflow, possibly enabling a Denial of Service attack. This happens when parsing an expression with several hundred levels of nesting, causing the process to abort immediately. This is a s...
CVE-2022-31101PUBLISHED: 2022-06-27prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2022-31103PUBLISHED: 2022-06-27
lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended on by [react-letter](https://github.com/mat-sz/react-letter),...
CVE-2022-32994PUBLISHED: 2022-06-27Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
CVE-2022-32995PUBLISHED: 2022-06-27Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
User Rank: Apprentice
11/3/2012 | 7:39:13 PM
Unlike many other biometrics, voice verification is a flexible technology that can be used-áin a text dependent or text independent fashion, presenting itself in a challenge response interface or operating in the background.-á-áLike other biometrics,-áit is a statistical process that results in a score as indicated in the article and-áhas been around a number of years.-á-áMany of the algorithms and research resides in the public domain and there are open source development environments.-á I do not agree that a company necesarily needs to engage with an expensive vendor as indicated.-á From my research and experience, I find that having a continuous good handle on your user set and biometric data is the key.-á-á
Once we go beyond a well defined user set, biometrics becomes-áone of the ultimate 'big data' applications in that we really only know how good the biometric is when we include all of the population.-á-áThis presents a challenge to performing all of the biometric processing on the mobile device since the biometric 'engine' will need to be updated over time as part of the biometric management application.
I have done an interesting biometrics TV series on biometrics in conjunction with NY Infragard.-á Some of the articles like, The Top 4 reasons to use Biometrics, are covered on the ibiometrics web-site blog.
Valene Skerpac, CISM, CISSP, PMP
Director, iBICS (iBiometrics, Inc.)