Aggregator
CVE-2003-1308 | fvwm 2.4.17/2.5.8 fvwm-menu-directory privileges management (EDB-23414 / BID-9161)
10 months 3 weeks ago
A vulnerability was found in fvwm 2.4.17/2.5.8. It has been declared as problematic. This vulnerability affects unknown code of the file fvwm-menu-directory. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2003-1308. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DEF CON 32 – AppSec Village – Defeating Secure Code Review GPT Hallucinations
10 months 3 weeks ago
Authors/Presenters:Wang Zhilong, Xinzhi Luo
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their timely DEF CON 32 erudite content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – AppSec Village – Defeating Secure Code Review GPT Hallucinations appeared first on Security Boulevard.
Marc Handelman
【知道创宇404实验室】警惕CVE-2024-47575针对Fortinet FortiManager的认证绕过漏洞
10 months 3 weeks ago
How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50%
10 months 3 weeks ago
The post How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50% appeared first on Strobes Security.
The post How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50% appeared first on Security Boulevard.
strobes
CVE-2021-20193 | GNU Tar up to 1.33 Input File src/list.c memory leak
10 months 3 weeks ago
A vulnerability was found in GNU Tar up to 1.33. It has been rated as problematic. Affected by this issue is some unknown functionality of the file src/list.c of the component Input File Handler. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2021-20193. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-43701 | ARM Compiler 5 Installation default permission
10 months 3 weeks ago
A vulnerability has been found in ARM Compiler 5, Compiler 6, Compiler for Embedded, Compiler for Embedded FuSa, Compiler for Linux, Development Studio, Development Studio Morello Edition, Forge, Mobile Studio, DS-5 Development Studio, Fast Models, GNU Toolchain, Installer Vulnerabilities, Keil MDK and Socrates and classified as critical. Affected by this vulnerability is an unknown functionality of the component Installation. The manipulation leads to incorrect default permissions.
This vulnerability is known as CVE-2022-43701. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-49014 | Linux Kernel up to 4.19.267/5.4.225/5.10.157/5.15.81/6.0.11 tun_detach use after free
10 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 4.19.267/5.4.225/5.10.157/5.15.81/6.0.11. It has been classified as critical. This affects the function tun_detach. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2022-49014. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49016 | Linux Kernel up to 5.15.81/6.0.11 mdiobus of_node_get/of_node_put reference count (543d917f691a/2708b3574404/cdde1560118f)
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.15.81/6.0.11. This issue affects the function of_node_get/of_node_put of the component mdiobus. The manipulation leads to improper update of reference count.
The identification of this vulnerability is CVE-2022-49016. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49018 | Linux Kernel up to 6.0.11 mptcp net/mptcp/protocol.c in_atomic stack-based overflow (d8e6c5500dbf/b4f166651d03)
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.0.11. Affected is the function in_atomic of the file net/mptcp/protocol.c of the component mptcp. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2022-49018. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
优秀创新成果!360安全大模型再获权威肯定
10 months 3 weeks ago
360安全大模型获2024中国国际数字经济博览会优秀创新成果
石家庄市政府与360达成战略合作 树立全国数字经济创新发展标杆
10 months 3 weeks ago
石家庄市政府与360携手 助推河北省数字安全和人工智能产业升级
'Shift Left' Gets Pushback, Triggers Security Soul Searching
10 months 3 weeks ago
A government report's criticism of the 100x metric often used to justify fixing software earlier in development fuels a growing debate over pushing responsibility for secure code onto developers.
Robert Lemos, Contributing Writer
流程速览 | “工业征途 安全守护”工业领域数据安全实践与创新论坛
10 months 3 weeks ago
点击查看,预约参会。
中国网络安全市场营收攀升背后的驱动力与待解难题
10 months 3 weeks ago
Gartner预测安全软件、安全服务和网络安全领域将迎来显著增长。
Intelligence Insights: October 2024
10 months 3 weeks ago
LummaC2 lurks thanks to PowerShell pasting in this month's edition of Intelligence Insights
The Red Canary Team
Ireland fines LinkedIn €310 million over targeted advertising
10 months 3 weeks ago
LinkedIn received a €310 million fine from the Irish Data Protection Commission for violating European Union's law related to the processing of personal data for behavioral analysis and targeted advertising. [...]
Bill Toulas
CVE-2018-1000021 | Git up to 2.15.1 Client input validation
10 months 3 weeks ago
A vulnerability classified as critical has been found in Git up to 2.15.1. This affects an unknown part of the component Client. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2018-1000021. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-47719 | Linux Kernel up to 6.6.53/6.10.12/6.11.1 iommufd io_pagetable.c ALIGN allocation of resources
10 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.53/6.10.12/6.11.1. It has been rated as problematic. This issue affects the function ALIGN of the file drivers/iommu/iommufd/io_pagetable.c of the component iommufd. The manipulation leads to allocation of resources.
The identification of this vulnerability is CVE-2024-47719. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Cisco fixes VPN DoS flaw discovered in password spray attacks
10 months 3 weeks ago
Cisco fixed a denial of service flaw in its Cisco ASA and Firepower Threat Defense (FTD) software, which was discovered during large-scale brute force attacks against Cisco VPN devices in April. [...]
Bill Toulas