Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-20001PUBLISHED: 2021-03-07An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
CVE-2020-28466PUBLISHED: 2021-03-07
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened r...
CVE-2021-27364PUBLISHED: 2021-03-07An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
CVE-2021-27365PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length...
CVE-2021-27363PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system...
User Rank: Ninja
12/22/2014 | 9:38:50 AM
In my opinion this event, because it involves North Korea, we should be looking at our privately owned (national) infrastructure of public utilities, water, electric... other power generation and banking. It's been proved many times over that some of these critical systems are open to the Internet, if not vulnerable to a dedicated script-kiddy. We (the US) invented STUXNET... Duqu... Flame and possibly others that we haven't heard about (yet). I don't know about you but there is no way that I can believe that America is the only "Nation State" with this capability, we're just the only ones whose been caught using it. We're wasting time.