Aggregator
CISA proposes new security requirements to protect govt, personal data
10 months 3 weeks ago
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is proposing security requirements to prevent adversary states from accessing American's personal data as well as government-related information. [...]
Bill Toulas
CVE-2024-48652 | Camaleon CMS 2.7.5 content group name cross site scripting
10 months 3 weeks ago
A vulnerability was found in Camaleon CMS 2.7.5 and classified as problematic. This issue affects some unknown processing. The manipulation of the argument content group name leads to cross site scripting.
The identification of this vulnerability is CVE-2024-48652. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-43698 | Kieback & Peter DDC4002 up to 1.17.6 weak credentials (icsa-24-291-05)
10 months 3 weeks ago
A vulnerability has been found in Kieback & Peter DDC4040e, DDC4020e, DDC4400e, DDC4200e, DDC4002e, DDC4400, DDC4200-L, DDC4200, DDC4100 and DDC4002 up to 1.17.6 and classified as very critical. This vulnerability affects unknown code. The manipulation leads to use of weak credentials.
This vulnerability was named CVE-2024-43698. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-48415 | itsourcecode Loan Management System 1.0 Borrowers Page cross site scripting
10 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in itsourcecode Loan Management System 1.0. This affects an unknown part of the component Borrowers Page. The manipulation of the argument lastname/firstname/middlename/address/contact_no/email/tax_id leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-48415. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-42643 | SmartDNS 46 fast_ping.c denial of service
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in SmartDNS 46. Affected by this issue is some unknown functionality of the file fast_ping.c. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-42643. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40494 | Keith Cullen FreeCoAP Packet coap_msg.c stack-based overflow
10 months 3 weeks ago
A vulnerability classified as critical was found in Keith Cullen FreeCoAP. Affected by this vulnerability is an unknown functionality of the file coap_msg.c of the component Packet Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-40494. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43812 | Kieback & Peter DDC4002 up to 1.17.6 Password Hash /etc/passwd insufficiently protected credentials (icsa-24-291-05)
10 months 3 weeks ago
A vulnerability classified as problematic has been found in Kieback & Peter DDC4040e, DDC4020e, DDC4400e, DDC4200e, DDC4002e, DDC4400, DDC4200-L, DDC4200, DDC4100 and DDC4002 up to 1.17.6. Affected is an unknown function of the file /etc/passwd of the component Password Hash Handler. The manipulation leads to insufficiently protected credentials.
This vulnerability is traded as CVE-2024-43812. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-40493 | Keith Cullen FreeCoAP 1.0 coap_client_exchange_blockwise2 null pointer dereference
10 months 3 weeks ago
A vulnerability was found in Keith Cullen FreeCoAP 1.0. It has been rated as problematic. This issue affects the function coap_client_exchange_blockwise2. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-40493. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-31029 | Keith Cullen FreeCoAP Packet test_coap_server.c server_handle_regular denial of service
10 months 3 weeks ago
A vulnerability was found in Keith Cullen FreeCoAP. It has been declared as problematic. This vulnerability affects the function server_handle_regular of the file test_coap_server.c of the component Packet Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-31029. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-46482 | Faveo-Helpdesk 2.0.3 Ticket Generation unrestricted upload
10 months 3 weeks ago
A vulnerability was found in Faveo-Helpdesk 2.0.3. It has been classified as critical. This affects an unknown part of the component Ticket Generation. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-46482. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-44812 | Online Complaint Site 1.0 /admin.index.php username/password sql injection
10 months 3 weeks ago
A vulnerability has been found in Online Complaint Site 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin.index.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is known as CVE-2024-44812. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-44331 | GStreamer RTSP server 1.25.0 Hexstream rtsp-media.c denial of service
10 months 3 weeks ago
A vulnerability was found in GStreamer RTSP server 1.25.0 and classified as problematic. Affected by this issue is some unknown functionality of the file gst-rtsp-server/rtsp-media.c of the component Hexstream Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-44331. The attack may be launched remotely. There is no exploit available.
vuldb.com
UK 'considering all options' to tackle cyberthreats, says government minister
10 months 3 weeks ago
The British government is “considering all options” to strengthen its response to cyberthreats, acc
The AI Fix #21: Virtual Trump, barking mad AI, and a robot dog with a flamethrower
10 months 3 weeks ago
Skip to contentNews and views from the world of artificial intelligence.In episode 2
Cybercriminals Exploiting Docker API Servers for SRBMiner Crypto Mining Attacks
10 months 3 weeks ago
Docker Security / Cloud SecurityBad actors have been observed targeting Docker remote API servers
CVE-2024-10231 | Google Chrome up to 130.0.6723.58 V8 type confusion
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Google Chrome. Affected is an unknown function of the component V8. The manipulation leads to type confusion.
This vulnerability is traded as CVE-2024-10231. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10230 | Google Chrome up to 130.0.6723.58 V8 type confusion
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Google Chrome. This issue affects some unknown processing of the component V8. The manipulation leads to type confusion.
The identification of this vulnerability is CVE-2024-10230. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10229 | Google Chrome up to 130.0.6723.58 Extensions Privilege Escalation
10 months 3 weeks ago
A vulnerability classified as problematic was found in Google Chrome. This vulnerability affects unknown code of the component Extensions. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2024-10229. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46483 | Xlight FTP Server 1.40/1.41/1.45/1.52 SFTP Server integer overflow
10 months 3 weeks ago
A vulnerability classified as critical has been found in Xlight FTP Server 1.40/1.41/1.45/1.52. This affects an unknown part of the component SFTP Server. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2024-46483. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com