Aggregator
New Research Reveals Spectre Vulnerability Persists in Latest AMD and Intel Processors
1 week 1 day ago
More than six years after the Spectre security flaw impacting modern CPU processors came to light, new research has found that the latest AMD and Intel processors are still susceptible to speculative execution attacks.
The attack, disclosed by ETH Zürich researchers Johannes Wikner and Kaveh Razavi, aims to undermine the Indirect Branch Predictor Barrier (IBPB) on x86 chips, a crucial mitigation
The Hacker News
CVE-2022-48672 | Linux Kernel up to 5.19.10 unflatten_dt_nodes off-by-one (Nessus ID 209785)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 5.19.10. It has been declared as problematic. Affected by this vulnerability is the function unflatten_dt_nodes. The manipulation leads to off-by-one.
This vulnerability is known as CVE-2022-48672. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26935 | Linux Kernel up to 6.9-rc1 /proc/scsi/${proc_name} scsi_proc_hostdir_rm allocation of resources (Nessus ID 209785)
1 week 1 day ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.9-rc1. This issue affects the function scsi_proc_hostdir_rm of the file /proc/scsi/${proc_name}. The manipulation leads to allocation of resources.
The identification of this vulnerability is CVE-2024-26935. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27065 | Linux Kernel up to 6.8.1 nf_tables comparison (Nessus ID 209785)
1 week 1 day ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.8.1. Affected by this vulnerability is an unknown functionality of the component nf_tables. The manipulation leads to incorrect comparison.
This vulnerability is known as CVE-2024-27065. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52836 | Linux Kernel up to 6.6.2 allocation of resources (Nessus ID 209785)
1 week 1 day ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.2. This affects an unknown part. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2023-52836. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47334 | Linux Kernel up to 5.13.3 ibmasm_init_remote_input_dev use after free (Nessus ID 209785)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 5.13.3 and classified as problematic. This issue affects the function ibmasm_init_remote_input_dev. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2021-47334. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47247 | Linux Kernel up to 5.12.12 mlx5e_rep_neigh_update use after free (b6447b72aca5/fb1a3132ee1a / Nessus ID 209785)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 5.12.12. It has been rated as critical. This issue affects the function mlx5e_rep_neigh_update. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2021-47247. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36923 | Linux Kernel up to 6.8.9 bad_inode uninitialized pointer (1b4cb6e91f19/6630036b7c22 / Nessus ID 209785)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.8.9. It has been classified as problematic. Affected is the function bad_inode. The manipulation leads to uninitialized pointer.
This vulnerability is traded as CVE-2024-36923. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36927 | Linux Kernel up to 6.6.30/6.8.9 ipv4 __ip_make_skb uninitialized resource (5db08343ddb1/f5c603ad4e6f/fc1092f51567 / Nessus ID 209785)
1 week 1 day ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.30/6.8.9. Affected is the function __ip_make_skb of the component ipv4. The manipulation leads to uninitialized resource.
This vulnerability is traded as CVE-2024-36927. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48713 | Linux Kernel up to 5.10.98/5.15.21/5.16.7 pt_buffer_region_size null pointer dereference (Nessus ID 209785)
1 week 1 day ago
A vulnerability classified as critical was found in Linux Kernel up to 5.10.98/5.15.21/5.16.7. This vulnerability affects the function pt_buffer_region_size. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2022-48713. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48755 | Linux Kernel up to 5.10.95/5.15.18/5.16.4 powerpc64 test_bpf denial of service (Nessus ID 209785)
1 week 1 day ago
A vulnerability classified as critical was found in Linux Kernel up to 5.10.95/5.15.18/5.16.4. Affected by this vulnerability is the function test_bpf of the component powerpc64. The manipulation leads to denial of service.
This vulnerability is known as CVE-2022-48755. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48768 | Linux Kernel up to 5.4.175/5.10.95/5.15.18/5.16.4 histogram kstrdup memory leak (Nessus ID 209785)
1 week 1 day ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.4.175/5.10.95/5.15.18/5.16.4. This issue affects the function kstrdup of the component histogram. The manipulation leads to memory leak.
The identification of this vulnerability is CVE-2022-48768. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48770 | Linux Kernel up to 5.10.95/5.15.18/5.16.4 bpf_get_task_stack return value (Nessus ID 209785)
1 week 1 day ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.95/5.15.18/5.16.4. Affected is the function bpf_get_task_stack. The manipulation leads to unchecked return value.
This vulnerability is traded as CVE-2022-48770. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38632 | Linux Kernel up to 6.6.32/6.9.3 vfio_intx_enable memory leak (0bd22a4966d5/35fef97c33f3/82b951e6fbd3 / Nessus ID 209785)
1 week 1 day ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.32/6.9.3. This affects the function vfio_intx_enable. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2024-38632. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
2 ундециллиона рублей: российские телеканалы выставили Google счёт с 36 нулями
1 week 1 day ago
Суммы исков продолжают увеличиваться с каждым днем.
在贝佐斯拒绝华盛顿邮报为贺锦丽背书之后愈 20 万订户取消订阅
1 week 1 day ago
在贝佐斯(Jeff Bezos)拒绝《华盛顿邮报》编委为民主党总统候选人贺锦丽(Kamala Harris)背书之后,愈 20 万订户取消了订阅,数名专栏作家和编委会成员辞职。《华盛顿邮报》有大约 250 万印刷版和数字版订户,截至周一中午,有超过 20 万人取消了数字订阅,占到了总订户的 8%。取消订阅的人数还在增长。《华盛顿邮报》发言人拒绝置评,理由是它是一家非上市公司。周日《华盛顿邮报》网站上浏览量最高的文章有三篇是在抨击贝佐斯的决定,其中排名第一的是专栏作家 Alexandra Petri 表态支持贺锦丽的文章。贝佐斯周一晚上发表评论,称此举是为了维持媒体的中立和独立性。
These 12 Open Source Projects Will Leave You Amazed
1 week 1 day ago
In today's complex software landscape, finding the right tools can be daunting. Luckily, open-source
CVE-2003-0414 | Sun One Application Server 7.0 on Windows Password information disclosure (XFDB-12096 / BID-7712)
1 week 1 day ago
A vulnerability was found in Sun One Application Server 7.0 on Windows. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure (Password).
This vulnerability is handled as CVE-2003-0414. Local access is required to approach this attack. There is no exploit available.
vuldb.com
OT PCAP Analyzer: Free PCAP analysis tool
1 week 1 day ago
EmberOT’s OT PCAP Analyzer, developed for the industrial security community, is a free tool providing a high-level overview of the devices and protocols in packet capture files. “The OT PCAP Analyzer was designed specifically with critical OT environments in mind. We’ve created a novel set of engines to gather and analyze network traffic at speed with unparalleled accuracy. This allows the free PCAP Analyzer to quickly identify OT devices, protocols, and how those elements interact. … More →
The post OT PCAP Analyzer: Free PCAP analysis tool appeared first on Help Net Security.
Mirko Zorz