Aggregator
VMware security advisory (AV24-597)
2 months 3 weeks ago
Canadian Centre for Cyber Security
CVE-2021-23017 | Oracle Communications Operations Monitor 3.4/4.2/4.3/4.4 nginx off-by-one (EDB-50973)
2 months 3 weeks ago
A vulnerability was found in Oracle Communications Operations Monitor 3.4/4.2/4.3/4.4. It has been classified as very critical. Affected is an unknown function of the component nginx. The manipulation leads to off-by-one.
This vulnerability is traded as CVE-2021-23017. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Web browser security: An overview (ITSAP.40.017)
2 months 3 weeks ago
Canadian Centre for Cyber Security
CVE-2008-0621 | SAP SAPSprint up to 6.28 memory corruption (EDB-5079 / Nessus ID 31121)
2 months 3 weeks ago
A vulnerability has been found in SAP SAPSprint up to 6.28 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2008-0621. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-0457 | Symantec Backupexec System Recovery 7.01 input validation (EDB-5078 / Nessus ID 30211)
2 months 3 weeks ago
A vulnerability classified as critical was found in Symantec Backupexec System Recovery 7.01. This vulnerability affects unknown code. The manipulation leads to improper input validation.
This vulnerability was named CVE-2008-0457. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-0772 | Mambo Com Doc index.php sid sql injection (EDB-5080 / BID-27679)
2 months 3 weeks ago
A vulnerability classified as critical was found in Mambo Com Doc. This vulnerability affects unknown code of the file index.php. The manipulation of the argument sid leads to sql injection.
This vulnerability was named CVE-2008-0772. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0714 | Mihalism Multi Host 3.0 users.php username sql injection (EDB-5074 / XFDB-40289)
2 months 3 weeks ago
A vulnerability was found in Mihalism Multi Host 3.0. It has been classified as critical. Affected is an unknown function of the file users.php. The manipulation of the argument username leads to sql injection.
This vulnerability is traded as CVE-2008-0714. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0719 | osCommerce Customer Testimonials 3.1 customer_testimonials.php testimonial_id sql injection (EDB-5075 / Nessus ID 31051)
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in osCommerce Customer Testimonials 3.1. This issue affects some unknown processing of the file customer_testimonials.php. The manipulation of the argument testimonial_id leads to sql injection.
The identification of this vulnerability is CVE-2008-0719. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0721 | Mambo Com Sermon 0.2 index.php gid sql injection (EDB-5076 / BID-27673)
2 months 3 weeks ago
A vulnerability has been found in Mambo Com Sermon 0.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument gid leads to sql injection.
This vulnerability is known as CVE-2008-0721. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
热点 | 又一汽车巨头遭勒索攻击,360为车企系好网络“安全带”
2 months 3 weeks ago
360护航“智驾”时代
US disrupts Anonymous Sudan DDoS operation, indicts 2 Sudanese brothers
2 months 3 weeks ago
The United States Department of Justice unsealed an indictment today against two Sudanese brothers suspected of being the operators of Anonymous Sudan, a notorious and dangerous hacktivist group known for conducting over 35,000 DDoS attacks in a year. [...]
Lawrence Abrams
CVE-2017-8907 | Atlassian Bamboo up to 5.15.6/6.0.0 Deployment Project access control (Nessus ID 101026 / BID-99090)
2 months 3 weeks ago
A vulnerability was found in Atlassian Bamboo up to 5.15.6/6.0.0. It has been rated as critical. This issue affects some unknown processing of the component Deployment Project Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2017-8907. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-9512 | Atlassian FishEye/Crucible up to 4.4.0 Permission Check mostActiveCommitters.do information disclosure (ID 803830)
2 months 3 weeks ago
A vulnerability classified as problematic was found in Atlassian FishEye and Crucible up to 4.4.0. This vulnerability affects unknown code of the file mostActiveCommitters.do of the component Permission Check. The manipulation leads to information disclosure.
This vulnerability was named CVE-2017-9512. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-12104 | wp-advanced-search Plugin 3.3.6 on WordPress Import sql injection
2 months 3 weeks ago
A vulnerability has been found in wp-advanced-search Plugin 3.3.6 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the component Import. The manipulation leads to sql injection.
This vulnerability is known as CVE-2020-12104. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2020-13822 | Elliptic Package 6.5.2 on node.js ECDSA Signature integer overflow
2 months 3 weeks ago
A vulnerability was found in Elliptic Package 6.5.2 on node.js. It has been classified as critical. This affects an unknown part of the component ECDSA Signature Handler. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2020-13822. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2020-28498 | elliptic secp256k1 elliptic/ec/key.js cryptographic issues (SNYK-JS-ELLIPTIC-1064899)
2 months 3 weeks ago
A vulnerability was found in elliptic and classified as problematic. This issue affects some unknown processing of the file elliptic/ec/key.js of the component secp256k1 Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2020-28498. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-24923 | Sendinblue Newsletter, SMTP, Email Marketing and Subscribe Forms Plugin Attribute cross site scripting
2 months 3 weeks ago
A vulnerability was found in Sendinblue Newsletter, SMTP, Email Marketing and Subscribe Forms Plugin on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Attribute Handler. The manipulation of the argument sib-statistics-date leads to cross site scripting.
This vulnerability was named CVE-2021-24923. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-24874 | Sendinblue Newsletter, SMTP, Email Marketing and Subscribe Forms Plugin cross site scripting
2 months 3 weeks ago
A vulnerability was found in Sendinblue Newsletter, SMTP, Email Marketing and Subscribe Forms Plugin 3.1.25 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument lang/pid leads to cross site scripting.
This vulnerability is traded as CVE-2021-24874. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-40306 | ECi Printanista Hub up to 2022-06-27 RSA Key-Generation /Login denial of service (SYSS-2022-042)
2 months 3 weeks ago
A vulnerability classified as problematic was found in ECi Printanista Hub up to 2022-06-27. This vulnerability affects unknown code of the file /Login of the component RSA Key-Generation. The manipulation leads to denial of service.
This vulnerability was named CVE-2022-40306. The attack needs to be done within the local network. There is no exploit available.
vuldb.com