Aggregator
CVE-2017-2467 | Apple iOS up to 10.2 ImageIO memory corruption (HT207617 / Nessus ID 99264)
1 week 1 day ago
A vulnerability was found in Apple iOS up to 10.2. It has been declared as critical. This vulnerability affects unknown code of the component ImageIO. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2467. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2467 | Apple macOS up to 10.12.3 ImageIO memory corruption (HT207615 / Nessus ID 99264)
1 week 1 day ago
A vulnerability was found in Apple macOS up to 10.12.3 and classified as critical. Affected by this issue is some unknown functionality of the component ImageIO. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-2467. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-1152 | memcached up to 1.4.2 memcached.c input validation (EDB-33850 / Nessus ID 45579)
1 week 1 day ago
A vulnerability, which was classified as problematic, was found in memcached. Affected is an unknown function of the file memcached.c. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2010-1152. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
FreeBuf早报 | OpenAI语音转录工具被曝严重幻觉;法国第二大电信运营商遭网络攻击
1 week 1 day ago
OpenAI的AI语音转写工具,那个号称近乎“人类水平”的Whisper,被曝幻觉严重。
CVE-2017-2432 | Apple tvOS up to 10.1 ImageIO memory corruption (HT207601 / Nessus ID 99264)
1 week 1 day ago
A vulnerability has been found in Apple tvOS up to 10.1 and classified as critical. This vulnerability affects unknown code of the component ImageIO. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2432. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
非虫大佬带你探索 eBPF安全开发与攻防对抗
1 week 1 day ago
eBPF 全称 extended Berkeley Packet Filter,中文意思是扩展的伯克利包过滤器。一般来说,要向内核添加新功能,需要修改内核源代码或者编写内核模块来实现。而 eBPF 允
近年来最大的医疗数据泄露事件!Change Healthcare 数据泄露影响超过1亿人
1 week 1 day ago
最近,联合健康集团(UnitedHealth)确认其子公司 Change Healthcare 遭受勒索软件攻击,导致超过 1 亿人的个人信息和医疗数据被盗。这是近年来最大的医疗数据泄露事件。事件起因
一种apc注入型的Gamarue病毒的变种
1 week 1 day ago
一概述二样本的基本信息MD5: 9de070f6864bc64e0fcac70a0c881cfbSHA1: 8b5c9c3f7ca2921542252b92d749696c75f617b2SHA256
App-Bound新工具可绕过谷歌浏览器的 Cookie 加密系统
1 week 1 day ago
该工具使用谷歌 浏览器内部的IElevator 服务,对存储在浏览器本地状态文件中的 App-Bound 加密密钥进行解密。
因“合规要求”,Linux Kernel 清除了11名俄罗斯开发者的维护者身份
1 week 1 day ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
Pwn2Own 2024爱尔兰黑客大赛落下帷幕 Master of Pwn 诞生
1 week 1 day ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
EDR & Antivirus Bypass to Gain Shell Access
1 week 1 day ago
EDR-Antivirus-Bypass-to-Gain-Shell-Access This repository contains a proof-of-concept (PoC) for bypassing EDR and antivirus solutions using a memory injection technique. The code executes shellcode that spawns a reverse shell, successfully evading detection by various security mechanisms. This project...
The post EDR & Antivirus Bypass to Gain Shell Access appeared first on Penetration Testing Tools.
ddos
LuLu: free open-source macOS firewall
1 week 1 day ago
LuLu is the free open-source macOS firewall that aims to block unauthorized (outgoing) network traffic unless explicitly approved by the user: Full details and usage instructions can be found here. Feature 100% free As...
The post LuLu: free open-source macOS firewall appeared first on Penetration Testing Tools.
ddos
CVE-2022-3786 | OpenSSL up to 3.0.6 x.509 Certificate buffer overflow (News 169687 / Nessus ID 209848)
1 week 1 day ago
A vulnerability was found in OpenSSL up to 3.0.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component x.509 Certificate Handler. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2022-3786. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-3602 | OpenSSL up to 3.0.6 X.509 Certificate buffer overflow (News 169687 / Nessus ID 209848)
1 week 1 day ago
A vulnerability classified as critical has been found in OpenSSL up to 3.0.6. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2022-3602. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-3602 | Oracle Essbase 21.5.3.0.0 Essbase Web Platform denial of service (Nessus ID 209848)
1 week 1 day ago
A vulnerability was found in Oracle Essbase 21.5.3.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Essbase Web Platform. The manipulation leads to denial of service.
This vulnerability is known as CVE-2022-3602. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2019-17657 | Fortinet FortiSwitch/FortiAnalyzer/FortiManager Admin WebUI HTTP Requests resource consumption (Nessus ID 209849)
1 week 1 day ago
A vulnerability, which was classified as problematic, was found in Fortinet FortiSwitch, FortiAnalyzer and FortiManager. This affects an unknown part of the component Admin WebUI. The manipulation as part of HTTP Requests leads to resource consumption.
This vulnerability is uniquely identified as CVE-2019-17657. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2021-44170 | Fortinet FortiOS/FortiProxy Command Line Argument stack-based overflow (Nessus ID 209850)
1 week 1 day ago
A vulnerability was found in Fortinet FortiOS and FortiProxy. It has been declared as critical. This vulnerability affects unknown code of the component Command Line Argument Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability was named CVE-2021-44170. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-29055 | Fortinet FortiOS/FortiProxy HTTP GET Request uninitialized pointer (FG-IR-22-086 / Nessus ID 209851)
1 week 1 day ago
A vulnerability classified as critical was found in Fortinet FortiOS and FortiProxy. This vulnerability affects unknown code of the component HTTP GET Request Handler. The manipulation leads to uninitialized pointer.
This vulnerability was named CVE-2022-29055. The attack can be initiated remotely. There is no exploit available.
vuldb.com