Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-34494PUBLISHED: 2022-06-26rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
CVE-2022-34495PUBLISHED: 2022-06-26rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
CVE-2020-27509PUBLISHED: 2022-06-26
Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. The payload executes when the recipient logs in...
CVE-2022-34491PUBLISHED: 2022-06-25
In the RSS extension for MediaWiki through 1.38.1, when the $wgRSSAllowLinkTag config variable was set to true, and a new RSS feed was created with certain XSS payloads within its description tags and added to the $wgRSSUrlWhitelist config variable, stored XSS could occur via MediaWiki's template sy...
CVE-2022-29931PUBLISHED: 2022-06-25Raytion 7.2.0 allows reflected Cross-site Scripting (XSS).
User Rank: Author
5/16/2014 | 7:17:36 AM
Through an assessment, it would most likely be noted that the majority of these security controls are enforced within two layers: 3-HOST and 4-INTRANET. Focusing on layer 3-HOST, there are any number of security controls that currently contribute - in varying percentages – to the endpoint protection; to which some can be surprisingly higher or lower than expected. And for the most part, security controls operating at layer 3-HOST also have counterparts that operate at layer 4-INTRANET.
"Postive security" for endpoint protection changes the perceived need for functional threat management into more attack surface reduction. As you've stated that by "putting the securtiy emphasis on the data itself, and then bolstering the endpoints, APIs, devices, etc. through which it's shared and stored", we are better positioned to be attack-agnostic and gain such benefits as I've outlined previously.
By implementing "positive security" controls at layer 3-HOST while enhancing security controls within the reminaing layers, future endpoint protection will focus on reducing attack surface risk and further enable data access from anywhere, at any time, and on any-device.