Aggregator
Чёрный континент в тёмной сети: 56% атак идут на три страны
2 months 1 week ago
Больше половины кибератак в Африке приходится на госсектор и финансы.
安全是最大的豪华:赛力斯集团首届网络安全白帽沙龙圆满举办
2 months 1 week ago
赛力斯集团网络安全白帽沙龙圆满举办
CVE-2015-2050 | D-Link DAP-1320 up to 1.10 privileges management (VU#184100 / SBV-50312)
2 months 1 week ago
A vulnerability, which was classified as very critical, has been found in D-Link DAP-1320 up to 1.10. This issue affects some unknown processing. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2015-2050. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-2340 | Granite Data Services 3.1.1-SNAPSHOT AMF Framework xml external entity reference (VU#279472 / SBV-57777)
2 months 1 week ago
A vulnerability was found in Granite Data Services 3.1.1-SNAPSHOT and classified as critical. Affected by this issue is some unknown functionality of the component AMF Framework. The manipulation leads to xml external entity reference.
This vulnerability is handled as CVE-2016-2340. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2016-5061 | Aternity up to 9 cross site scripting (VU#706359 / BID-93210)
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in Aternity up to 9. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2016-5061. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2016-5062 | Aternity up to 9 getMBeansFromURL resource transfer (VU#706359 / BID-93208)
2 months 1 week ago
A vulnerability, which was classified as very critical, was found in Aternity up to 9. Affected is an unknown function of the component getMBeansFromURL. The manipulation leads to incorrect resource transfer.
This vulnerability is traded as CVE-2016-5062. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2015-2877 | Linux Kernel up to 4.x KSM information disclosure (VU#935424 / BID-76256)
2 months 1 week ago
A vulnerability was found in Linux Kernel up to 4.x. It has been rated as problematic. This issue affects some unknown processing of the component KSM. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2015-2877. The attack may be initiated remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to change the configuration settings.
vuldb.com
CVE-2016-10029 | QEMU Virtio GPU Device Emulator virtio_gpu_set_scanout out-of-bounds (Nessus ID 95018 / ID 196757)
2 months 1 week ago
A vulnerability has been found in QEMU and classified as problematic. Affected by this vulnerability is the function virtio_gpu_set_scanout of the component Virtio GPU Device Emulator. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2016-10029. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2016-8232 | Lenovo IBM BladeCenter prior 66Z Advanced Management Module DOM cross site scripting (XFDB-121443 / BID-95839)
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in Lenovo IBM BladeCenter. This affects an unknown part of the component Advanced Management Module. The manipulation leads to cross site scripting (DOM).
This vulnerability is uniquely identified as CVE-2016-8232. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-4877 | GNU wget up to 1.15 FTP path traversal (Bug 1139181 / VU#685996)
2 months 1 week ago
A vulnerability was found in GNU wget up to 1.15 and classified as problematic. Affected by this issue is some unknown functionality of the component FTP Handler. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2014-4877. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
From the dreamhouse to the SOC: Ken’s guide to security
2 months 1 week ago
Unboxing some of the year’s most prevalent threats with detection and prevention guidance from Barbie’s boyfriend
Laura Brosnan
更多 X 用户逃到 Bluesky
2 months 1 week ago
美国大选结束一周内,Bluesky 增加逾 70 万新用户。该平台的全球用户达到 1450 万,而 9 月份是 900 万。社媒研究员 Axel Bruns 称,Bluesky 为偏向自由派的 X 用户提供了一座庇护所,那里没有极右翼、虚假信息、仇恨言论、机器人账号等。Bluesky 最初是 Twitter 的一个内部项目,在 2022 年成为一家独立公司,现在主要由 CEO Jay Graber 拥有。Bluesky 称,在 X 于 9 月被巴西禁止访问的一周内,它增加了 300 万新用户,在 X 宣布允许用户查看已将其拉黑用户发布的帖子后的两天内增加了 120 万新用户。Bluesky 在苹果美国 App Store 的社交网络类下载量仅次于 Threads,后者报告有 2.75 亿月活跃用户。
Wish Stealer:针对 Discord、浏览器和加密货币钱包的新恶意软件
2 months 1 week ago
安全客
披头士《Now And Then》成为首部获格莱美提名的 AI 辅助创作的歌曲
2 months 1 week ago
披头士乐队的《Now And Then》成为首部获格莱美奖提名的 AI 辅助创作的歌曲,它赢得了最佳唱片和最佳摇滚表演奖提名。《Now And Then》是乐队解散逾五十年后,四名披头士成
Fraudsters Abuse DocuSign API for Legit-Looking Invoices
2 months 1 week ago
I didn’t see much visibili
Ghostscript 更新修补了六个严重漏洞: 代码执行、缓冲区溢出和路径遍历风险
2 months 1 week ago
安全客
美国零售商泄露5700万用户数据
2 months 1 week ago
主站 分类 漏洞 工具 极客
FACT_core:一款固件安全分析和比较工具
2 months 1 week ago
FACT_core是一款功能强大的固件安全分析和比较工具,该工具旨在自动化大部分固件分析过程,以辅助广大研究人员完成固件安全分析等任务。
CodeQL 入门和基本使用
2 months 1 week ago
error code: 521