Aggregator
Randall Munroe’s XKCD ‘Ferris Wheels’
2 months 3 weeks ago
via the comic & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Ferris Wheels’ appeared first on Security Boulevard.
Marc Handelman
Randall Munroe’s XKCD ‘Ferris Wheels’
2 months 3 weeks ago
Application Security Check Up
Adventures in Shellcode Obfuscation! Part 10: Shellcode as MAC Addresses
2 months 3 weeks ago
by Mike Saunders, Principal Security Consultant This blog is the tenth in a series of blogs on obfuscation techniques for hiding shellcode. You can find the rest of […]
Red Siege
CVE-2024-7384 | Acyba AcyMailing Plugin up to 9.7.2 on WordPress acym_extractArchive unrestricted upload
2 months 3 weeks ago
A vulnerability was found in Acyba AcyMailing Plugin up to 9.7.2 on WordPress. It has been declared as critical. Affected by this vulnerability is the function acym_extractArchive. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2024-7384. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-33656 | AMI AptioV up to 5.36 DXE Module privileges management
2 months 3 weeks ago
A vulnerability was found in AMI AptioV up to 5.36. It has been classified as critical. Affected is an unknown function of the component DXE Module. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2024-33656. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2024-33657 | AMI AptioV up to 5.36 memory corruption
2 months 3 weeks ago
A vulnerability was found in AMI AptioV up to 5.36 and classified as critical. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2024-33657. An attack has to be approached locally. There is no exploit available.
vuldb.com
What’s New in CodeSonar 8.2
2 months 3 weeks ago
CodeSonar 8.2 is a significant upgrade, containing new features and integrations, improved compiler and language support, and more checkers. The highlights are listed below; for more complete details, please consult the Release Notes. We recommend customers update to this version of CodeSonar as soon as possible to get access to these benefits. Explore the latest…
The post What’s New in CodeSonar 8.2 appeared first on CodeSecure.
The post What’s New in CodeSonar 8.2 appeared first on Security Boulevard.
Sean Evoy
What’s New in CodeSonar 8.2
2 months 3 weeks ago
CodeSonar 8.2 is a significant upgrade, containing new features and integrations, impro
Life at SpecterOps: The Red Team Dream
2 months 3 weeks ago
Duane Michael
Life at SpecterOps: The Red Team Dream
2 months 3 weeks ago
CVE-2024-21690 | Atlassian Confluence Data Center/Confluence Server up to 8.9.5 cross-site request forgery
2 months 3 weeks ago
A vulnerability has been found in Atlassian Confluence Data Center and Confluence Server up to 8.9.5 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-21690. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43027 | Draytek Vigor 3900/Vigor 2960/Vigor 300B prior 1.5.1.5_Beta cgi-bin/mainfunction.cgi action command injection
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Draytek Vigor 3900, Vigor 2960 and Vigor 300B. This affects an unknown part of the file cgi-bin/mainfunction.cgi. The manipulation of the argument action leads to command injection.
This vulnerability is uniquely identified as CVE-2024-43027. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39344 | Docusign API Package 8.142.14 on Salesforce information disclosure
2 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Docusign API Package 8.142.14 on Salesforce. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-39344. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-43410 | Eugeny russh up to 0.44.0 allocation of resources
2 months 3 weeks ago
A vulnerability classified as critical was found in Eugeny russh up to 0.44.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2024-43410. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-26328 | OpenText Performance Center 12.63 on Windows cross site scripting
2 months 3 weeks ago
A vulnerability classified as problematic has been found in OpenText Performance Center 12.63 on Windows. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2022-26328. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-41675 | ckan up to 2.10.4 datatables_view cross site scripting (GHSA-r3jc-vhf4-6v32)
2 months 3 weeks ago
A vulnerability was found in ckan up to 2.10.4. It has been rated as problematic. This issue affects the function datatables_view. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-41675. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-26327 | OpenText Performance Center 12.63 on Windows information disclosure
2 months 3 weeks ago
A vulnerability was found in OpenText Performance Center 12.63 on Windows. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2022-26327. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41937 | Apache Airflow up to 2.9.x cross site scripting
2 months 3 weeks ago
A vulnerability was found in Apache Airflow up to 2.9.x. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-41937. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
New MoonPeak RAT Linked to North Korean Threat Group UAT-5394
2 months 3 weeks ago
The MoonPeak RAT as used by UAT-5394 showed a possible connection to North Korean threat Kimsuky