Aggregator
DeepSeek(R1) vs Gpt-o3-mini(-high)
2 months 3 weeks ago
DeepSeek(R1) vs Gpt-o3-mini(-high)
2 months 3 weeks ago
DeepSeek(R1) vs Gpt-o3-mini(-high)
2 months 3 weeks ago
Shiro CVE-2023-22602 补丁失效导致的路径匹配绕过
2 months 3 weeks ago
该漏洞是springboot2.6后CVE-2020-17510漏洞补丁失效导致的,本次修复可以让其重新生效
CVE-2012-1470 | ocPortal up to 7.1.5 code_editor.php cross site scripting (EDB-37022 / ID 103459)
2 months 3 weeks ago
A vulnerability was found in ocPortal and classified as problematic. This issue affects some unknown processing of the file code_editor.php. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2012-1470. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Shiro CVE-2022-40664 请求转发导致的验证绕过
2 months 3 weeks ago
请求转发导致路径绕过。该漏洞的补丁需要额外配置才生效
CVE-2006-3815 | Linux-ha heartbeat 2.0.5 Shared Memory heartbeat.c access control (EDB-28287 / Nessus ID 22670)
2 months 3 weeks ago
A vulnerability was found in Linux-ha heartbeat 2.0.5 and classified as problematic. This issue affects some unknown processing of the file heartbeat.c of the component Shared Memory. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2006-3815. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2001-0647 | Orange Web Server 2.1 GET Request denial of service (EDB-20655 / Nessus ID 10636)
2 months 3 weeks ago
A vulnerability was found in Orange Web Server 2.1. It has been declared as problematic. This vulnerability affects unknown code of the component GET Request Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2001-0647. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2019-6706 | Lua 5.3.5 lapi.c lua_upvaluejoin Argument use after free (FEDORA-2019-ee57bda7ae / EDB-46246)
2 months 3 weeks ago
A vulnerability was found in Lua 5.3.5. It has been declared as problematic. This vulnerability affects the function lua_upvaluejoin of the file lapi.c. The manipulation as part of Argument leads to use after free.
This vulnerability was named CVE-2019-6706. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-2926 | ISC BIND up to 9.5.0a5 Random Number Generator (VU#252735 / EDB-4266)
2 months 3 weeks ago
A vulnerability classified as problematic was found in ISC BIND up to 9.5.0a5. This vulnerability affects unknown code of the component Random Number Generator. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2007-2926. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36899 | Linux Kernel up to 6.6.30/6.8.9 cdev gpio_chrdev_release use after free (95ca7c90eaf5/ca710b5f40b8/02f6b0e1ec7e / Nessus ID 207776)
2 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.30/6.8.9. It has been classified as critical. This affects the function gpio_chrdev_release of the component cdev. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-36899. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57887 | Linux Kernel up to 6.6.69/6.12.8 drm adv7533_attach_dsi use after free (Nessus ID 214781)
2 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.69/6.12.8. It has been classified as critical. This affects the function adv7533_attach_dsi of the component drm. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-57887. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57892 | Linux Kernel up to 6.6.69/6.12.8 ocfs2_get_next_id use after free (Nessus ID 214781)
2 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.69/6.12.8 and classified as critical. This issue affects the function ocfs2_get_next_id. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-57892. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56631 | Linux Kernel up to 6.6.65/6.12.4 scsi sg_release reference count (Nessus ID 214453)
2 months 3 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.65/6.12.4. Affected is the function sg_release of the component scsi. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2024-56631. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35967 | Linux Kernel up to 5.10.215/6.1.86/6.6.27/6.8.6 Bluetooth include/linux/sockptr.h sco_sock_setsockopt out-of-bounds (Nessus ID 213100)
2 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 5.10.215/6.1.86/6.6.27/6.8.6 and classified as problematic. This issue affects the function sco_sock_setsockopt in the library include/linux/sockptr.h of the component Bluetooth. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-35967. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50009 | Linux Kernel up to 6.11.2 cpufreq cpufreq_cpu_get null pointer dereference (5f250d44b819/5493f9714e4c / Nessus ID 213018)
2 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.11.2. It has been declared as critical. This vulnerability affects the function cpufreq_cpu_get of the component cpufreq. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-50009. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-1554 | Alexphpteam Alex Guestbook 3.12 livre_include.php chem_absolu file inclusion (EDB-24638 / Nessus ID 14830)
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Alexphpteam Alex Guestbook 3.12. This issue affects some unknown processing of the file livre_include.php. The manipulation of the argument chem_absolu leads to file inclusion.
The identification of this vulnerability is CVE-2004-1554. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-1864 | Linux Kernel up to 2.6.16.8 Filesystem path traversal (Bug 189435 / EDB-27766)
2 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 2.6.16.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Filesystem. The manipulation leads to path traversal.
This vulnerability is known as CVE-2006-1864. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-4905 | Accscripts Acc Statistics 1.1 index.php cross-site request forgery (EDB-10406 / SA37694)
2 months 3 weeks ago
A vulnerability classified as problematic has been found in Accscripts Acc Statistics 1.1. This affects an unknown part of the file index.php. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2009-4905. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com