Aggregator
24年9月必修安全漏洞清单|腾讯安全威胁情报中心
10 months 3 weeks ago
CVE-1999-0409 | SuSE Linux 3.5/5.2 gnuplot memory corruption (EDB-19254 / BID-319)
10 months 3 weeks ago
A vulnerability classified as problematic was found in SuSE Linux 3.5/5.2. This vulnerability affects unknown code of the component gnuplot. The manipulation leads to memory corruption.
This vulnerability was named CVE-1999-0409. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack
10 months 3 weeks ago
A new spear-phishing campaign targeting Brazil has been found delivering a banking malware called Astaroth (aka Guildma) by making use of obfuscated JavaScript to slip past security guardrails.
"The spear-phishing campaign's impact has targeted various industries, with manufacturing companies, retail firms, and government agencies being the most affected," Trend Micro said in a new analysis.
"
The Hacker News
彗星又来的那一夜
10 months 3 weeks ago
拍摄于 2024 年 10 月 15 日傍晚,均为单张曝光。
去年年初去追了 ZTF 彗星。因为设备和技术限制只拍到一个小绿点,兴奋不已。没想到这只是前菜。最近又被紫金山-阿特拉斯彗星的消息刷屏。
九月底彗星还是晨星的那几天,我正好又在加那利岛,但是连续几天都不想四五点早起上山。
拖到上周末开始北半球可以在日落后观赏,我追了三天都没见到,复盘才发现误会了时间点,走太早了。15 日打算最后尝试一次,越往后亮度会锐减,能不能继续看到就不好说了。
蹭朋友车上了山,原本影响观测的云变成了脚下的云海。日落后半小时就已经可以用相机捕捉到彗星,但这时候比较难定位。接下来的半小时逐渐变亮,连彗尾一起肉眼可见。震惊得无以言表。无需长曝光,在手机取景器实时预览里就非常清晰。
难以想象当年海尔-波普甚至池谷-关彗星该有多壮观。
彗星又来的那一夜
10 months 3 weeks ago
拍摄于 2024 年 10 月 15 日傍晚,均为单张曝光。
去年年初去追了 ZTF 彗星。因为设备和技术限制只拍到一个小绿点,兴奋不已。没想到这只是前菜。最近又被紫金山-阿特拉斯彗星的消息刷屏。
九月底彗星还是晨星的那几天,我正好又在加那利岛,但是连续几天都不想四五点早起上山。
拖到上周末开始北半球可以在日落后观赏,我追了三天都没见到,复盘才发现误会了时间点,走太早了。15 日打算最后尝试一次,越往后亮度会锐减,能不能继续看到就不好说了。
蹭朋友车上了山,原本影响观测的云变成了脚下的云海。日落后半小时就已经可以用相机捕捉到彗星,但这时候比较难定位。接下来的半小时逐渐变亮,连彗尾一起肉眼可见。震惊得无以言表。无需长曝光,在手机取景器实时预览里就非常清晰。
难以想象当年海尔-波普甚至池谷-关彗星该有多壮观。
彗星又来的那一夜
10 months 3 weeks ago
拍摄于 2024 年 10 月 15 日傍晚,均为单张曝光。
去年年初去追了 ZTF 彗星。因为设备和技术限制只拍到一个小绿点,兴奋不已。没想到这只是前菜。最近又被紫金山-阿特拉斯彗星的消息刷屏。
九月底彗星还是晨星的那几天,我正好又在加那利岛,但是连续几天都不想四五点早起上山。
拖到上周末开始北半球可以在日落后观赏,我追了三天都没见到,复盘才发现误会了时间点,走太早了。15 日打算最后尝试一次,越往后亮度会锐减,能不能继续看到就不好说了。
蹭朋友车上了山,原本影响观测的云变成了脚下的云海。日落后半小时就已经可以用相机捕捉到彗星,但这时候比较难定位。接下来的半小时逐渐变亮,连彗尾一起肉眼可见。震惊得无以言表。无需长曝光,在手机取景器实时预览里就非常清晰。
难以想象当年海尔-波普甚至池谷-关彗星该有多壮观。
彗星又来的那一夜
10 months 3 weeks ago
拍摄于 2024 年 10 月 15 日傍晚,均为单张曝光。
去年年初去追了 ZTF 彗星。因为设备和技术限制只拍到一个小绿点,兴奋不已。没想到这只是前菜。最近又被紫金山-阿特拉斯彗星的消息刷屏。
九月底彗星还是晨星的那几天,我正好又在加那利岛,但是连续几天都不想四五点早起上山。
拖到上周末开始北半球可以在日落后观赏,我追了三天都没见到,复盘才发现误会了时间点,走太早了。15 日打算最后尝试一次,越往后亮度会锐减,能不能继续看到就不好说了。
蹭朋友车上了山,原本影响观测的云变成了脚下的云海。日落后半小时就已经可以用相机捕捉到彗星,但这时候比较难定位。接下来的半小时逐渐变亮,连彗尾一起肉眼可见。震惊得无以言表。无需长曝光,在手机取景器实时预览里就非常清晰。
难以想象当年海尔-波普甚至池谷-关彗星该有多壮观。
Sipulitie: Финляндия закрыла крупный маркетплейс нелегальных товаров
10 months 3 weeks ago
Расследование раскрывает тайны миллионного даркнет-рынка.
CVE-2024-3408 | man-group dtale /update-settings SECRET_KEY hard-coded key
10 months 3 weeks ago
A vulnerability was found in man-group dtale. It has been classified as very critical. Affected is an unknown function of the file /update-settings. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key
.
This vulnerability is traded as CVE-2024-3408. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-36735 | Oneflow 0.9.1 oneflow.eye Privilege Escalation
10 months 3 weeks ago
A vulnerability was found in Oneflow 0.9.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument oneflow.eye leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-36735. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-37154 | Evmos up to 18.1.0 improper authorization (GHSA-7hrh-v6wp-53vw)
10 months 3 weeks ago
A vulnerability classified as critical has been found in Evmos up to 18.1.0. Affected is an unknown function. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2024-37154. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-37153 | Evmos up to 18.0.x sender control flow (GHSA-xgr7-jgq3-mhmc)
10 months 3 weeks ago
A vulnerability has been found in Evmos up to 18.0.x and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument sender leads to incorrect control flow.
This vulnerability was named CVE-2024-37153. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36730 | Oneflow 0.9.1 oneflow.zeros/ones denial of service
10 months 3 weeks ago
A vulnerability was found in Oneflow 0.9.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument oneflow.zeros/ones leads to denial of service.
This vulnerability is known as CVE-2024-36730. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-3110 | mintplex-labs anything-llm up to 0.x cross site scripting
10 months 3 weeks ago
A vulnerability classified as problematic has been found in mintplex-labs anything-llm up to 0.x. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-3110. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22524 | dnspod-sr 0dfbd37 buffer overflow (Issue 60)
10 months 3 weeks ago
A vulnerability was found in dnspod-sr 0dfbd37. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2024-22524. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-22525 | dnspod-sr 0dfbd37 memory corruption (Issue 61)
10 months 3 weeks ago
A vulnerability classified as critical has been found in dnspod-sr 0dfbd37. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-22525. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-30088 | Microsoft Windows up to Server 2022 23H2 Kernel toctou
10 months 3 weeks ago
A vulnerability has been found in Microsoft Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component Kernel. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2024-30088. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-39322 | aimeos ai-admin-jsonadm authorization
10 months 3 weeks ago
A vulnerability was found in aimeos ai-admin-jsonadm. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to incorrect authorization.
This vulnerability was named CVE-2024-39322. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7038 | open-webui up to 0.3.8 Admin Setting information disclosure
10 months 3 weeks ago
A vulnerability has been found in open-webui up to 0.3.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Admin Setting Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-7038. The attack can be launched remotely. There is no exploit available.
vuldb.com