Aggregator
CVE-2014-7631 | Texasweddingmall Villa Antonia 1 X.509 Certificate cryptographic issues (VU#582497)
10 months 3 weeks ago
A vulnerability was found in Texasweddingmall Villa Antonia 1. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-7631. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2014-7630 | Candycaneapps Fling Gold 1.1.3 X.509 Certificate cryptographic issues (VU#582497)
10 months 3 weeks ago
A vulnerability was found in Candycaneapps Fling Gold 1.1.3. It has been declared as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-7630. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
Patch-22: The Catch of Waiting to Fix Cybersecurity Vulnerabilities
10 months 3 weeks ago
One of the biggest dilemmas for security teams is when to patch vulnerabilities. This is a classic “Patch-22” situation—patching immediately can be time-consuming and disruptive, but waiting leaves your organization exposed to cyber threats. It’s a tough balancing act between fixing vulnerabilities and maintaining business continuity. With cyberattacks evolving and becoming more frequent, waiting to […]
The post Patch-22: The Catch of Waiting to Fix Cybersecurity Vulnerabilities appeared first on VERITI.
The post Patch-22: The Catch of Waiting to Fix Cybersecurity Vulnerabilities appeared first on Security Boulevard.
Michael Greenberg
CVE-2019-11358 | Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7 Apache Commons FileUpload cross site scripting (Nessus ID 208606 / ID 176919)
10 months 3 weeks ago
A vulnerability classified as critical was found in Oracle Insurance Data Foundation 8.0.4/8.0.5/8.0.6/8.0.7. This vulnerability affects unknown code of the component Apache Commons FileUpload. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2019-11358. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-11358 | Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7 Apache Commons FileUpload cross site scripting (Nessus ID 208606 / ID 176919)
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle Insurance IFRS 17 Analyzer 8.0.6/8.0.7. This issue affects some unknown processing of the component Apache Commons FileUpload. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2019-11358. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-11358 | Oracle Insurance Performance Insight 8.0.7 Spring Framework cross site scripting (Nessus ID 208606 / ID 176919)
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Oracle Insurance Performance Insight 8.0.7. Affected is an unknown function of the component Spring Framework. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2019-11358. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-11358 | Oracle Hospitality Guest Access 4.2/4.2.1 jackson-databind cross site scripting (Nessus ID 208606 / ID 176919)
10 months 3 weeks ago
A vulnerability was found in Oracle Hospitality Guest Access 4.2/4.2.1. It has been classified as critical. Affected is an unknown function of the component jackson-databind. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2019-11358. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-11358 | Oracle Financial Services Market Risk Measurement 8.0.5/8.0.6/8.0.8 Bouncy Castle Java Library cross site scripting (Nessus ID 208606 / ID 176919)
10 months 3 weeks ago
A vulnerability was found in Oracle Financial Services Market Risk Measurement and Management 8.0.5/8.0.6/8.0.8. It has been declared as critical. This vulnerability affects unknown code of the component Bouncy Castle Java Library. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2019-11358. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 15
10 months 3 weeks ago
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Over 300,000! GorillaBot: The New King of DDoS Attacks Hidden cryptocurrency mining and theft campaign affected over […]
Pierluigi Paganini
CVE-2008-0140 | Uebimiau Webmail 2.7.2/2.7.10 error.php selected_theme path traversal (EDB-4846 / XFDB-39460)
10 months 3 weeks ago
A vulnerability was found in Uebimiau Webmail 2.7.2/2.7.10. It has been rated as critical. This issue affects some unknown processing of the file error.php. The manipulation of the argument selected_theme leads to path traversal.
The identification of this vulnerability is CVE-2008-0140. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0133 | Thomas Perez Tribisur 2.1 cat_main.php cat sql injection (EDB-4840 / XFDB-39443)
10 months 3 weeks ago
A vulnerability classified as critical was found in Thomas Perez Tribisur 2.1. This vulnerability affects unknown code of the file cat_main.php. The manipulation of the argument cat leads to sql injection.
This vulnerability was named CVE-2008-0133. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0210 | Uebimiau Webmail 2.7.2/2.7.10 sess[auth]=1 improper authentication (EDB-4846 / BID-27154)
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Uebimiau Webmail 2.7.2/2.7.10. This issue affects some unknown processing. The manipulation of the argument sess[auth]=1 leads to improper authentication.
The identification of this vulnerability is CVE-2008-0210. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0222 | WordPress filemanager 1.2 File Upload ajaxfilemanager.php code injection (EDB-4844 / XFDB-39462)
10 months 3 weeks ago
A vulnerability classified as critical has been found in WordPress filemanager 1.2. Affected is an unknown function of the file ajaxfilemanager.php of the component File Upload. The manipulation leads to code injection.
This vulnerability is traded as CVE-2008-0222. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0224 | RunCMS 1.5.3/1.6/1.6.1 index.php Client-Ip sql injection (EDB-4845 / Nessus ID 29868)
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in RunCMS 1.5.3/1.6/1.6.1. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument Client-Ip leads to sql injection.
This vulnerability is handled as CVE-2008-0224. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-6288 | Niek Albers CoolPlayer 216 cpi_playlist.c main_skin_open memory corruption (EDB-4839 / XFDB-30863)
10 months 3 weeks ago
A vulnerability was found in Niek Albers CoolPlayer 216. It has been rated as problematic. This issue affects the function main_skin_open of the file cpi_playlist.c. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2006-6288. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0137 | SNETWORKS PHP CLASSIFIEDS 5.0 config.inc.php path_escape sql injection (EDB-4838 / XFDB-39468)
10 months 3 weeks ago
A vulnerability was found in SNETWORKS PHP CLASSIFIEDS 5.0 and classified as critical. Affected by this issue is some unknown functionality of the file config.inc.php. The manipulation of the argument path_escape leads to sql injection.
This vulnerability is handled as CVE-2008-0137. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Security Affairs newsletter Round 493 by Pierluigi Paganini – INTERNATIONAL EDITION
10 months 3 weeks ago
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. A cyber attack hit Iranian government sites and nuclear facilities Ransomware operators exploited Veeam Backup & Replication flaw […]
Pierluigi Paganini
CVE-2024-44934 | Linux Kernel up to 5.15.164/6.1.104/6.6.45/6.10.4 br_multicasg_gc use after free (Nessus ID 208811)
10 months 3 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 5.15.164/6.1.104/6.6.45/6.10.4. This vulnerability affects the function br_multicasg_gc. The manipulation leads to use after free.
This vulnerability was named CVE-2024-44934. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-29040 | tpm2-tss Quote Data Fapi_VerifyQuote deserialization (Nessus ID 208843)
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in tpm2-tss. This issue affects the function Fapi_VerifyQuote of the component Quote Data Handler. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-29040. Access to the local network is required for this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com