Aggregator
CVE-2025-20128 | Cisco Secure Endpoint up to 8.1.7.21512 ClamAV heap-based overflow (cisco-sa-clamav-ole2-H549rphA / Nessus ID 214849)
3 months ago
A vulnerability, which was classified as critical, has been found in Cisco Secure Endpoint. Affected by this issue is some unknown functionality of the component ClamAV. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2025-20128. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
[Darknetlive Archive] Dream Vendor CaliCartel Admits Drug Trafficking Conspiracy
3 months ago
[Darknetlive Archive] Dream Vendor CaliCartel Admits Drug Trafficking Conspiracy
Dark Web Informer - Cyber Threat Intelligence
CVE-2001-0006 | Microsoft Windows NT 4.0 Winsock2ProtocolCatalogMutex denial of service (MS01-003 / EDB-20596)
3 months ago
A vulnerability, which was classified as problematic, has been found in Microsoft Windows NT 4.0. This issue affects some unknown processing of the component Winsock2ProtocolCatalogMutex. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2001-0006. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
FBI, Dutch Police Disrupt ‘Manipulaters’ Phishing Gang
3 months ago
The FBI and authorities in The Netherlands this week seized a number of servers and domains for a hugely popular spam and malware dissemination service operating out of Pakistan. The proprietors of the service, who use the collective nickname "The Manipulaters," have been the subject of three stories published here since 2015. The FBI said the main clientele are organized crime groups that try to trick victim companies into making payments to a third party.
BrianKrebs
Tenable to Acquire Vulcan Cyber to Boost Exposure Management Focus
3 months ago
The deal, expected to close this quarter, will give Tenable One Exposure Management much-needed integration with over 100 third-party security tools and platforms.
Jeffrey Schwartz
CVE-2009-4017 | PHP 5.2.11/5.3.0 denial of service (EDB-10242 / Nessus ID 42918)
3 months ago
A vulnerability classified as problematic was found in PHP 5.2.11/5.3.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to denial of service.
This vulnerability is known as CVE-2009-4017. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-1018 | PHP up to 4.3.10/5.0.3 Upload magic_quotes_gpc path traversal (EDB-24854 / Nessus ID 18091)
3 months ago
A vulnerability, which was classified as problematic, has been found in PHP up to 4.3.10/5.0.3. Affected by this issue is the function magic_quotes_gpc of the component Upload Handler. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2004-1018. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-1018 | PHP up to 4.3.10/5.0.3 exif_read_data Long Section Name memory corruption (EDB-24854 / Nessus ID 18091)
3 months ago
A vulnerability classified as critical was found in PHP up to 4.3.10/5.0.3. Affected by this vulnerability is the function exif_read_data. The manipulation as part of Long Section Name leads to memory corruption.
This vulnerability is known as CVE-2004-1018. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Creating realistic, secure test data for Databricks
3 months ago
Databricks is a data analytics platform built to handle the scale and complexity of today’s data. Learn how Tonic integrates seamlessly with Databricks to generate synthetic test data based on production data that is both complex enough to be valuable and secure enough to protect user privacy.
The post Creating realistic, secure test data for Databricks appeared first on Security Boulevard.
Expert Insights on Synthetic Data from the Tonic.ai Blog
Code-Scanning Tool's License at Heart of Security Breakup
3 months ago
Nine application security toolmakers band together to fork the popular Semgrep code-scanning project, touching off a controversy over access to features and fairness.
Robert Lemos, Contributing Writer
Southeast Supply, Inc. Has Fallen Victim to 8BASE Ransomware
3 months ago
Southeast Supply, Inc. Has Fallen Victim to 8BASE Ransomware
Dark Web Informer - Cyber Threat Intelligence
Mr Hamza Targeted the Website of Booking.com
3 months ago
Mr Hamza Targeted the Website of Booking.com
Dark Web Informer - Cyber Threat Intelligence
Microsoft improves text contrast for all Windows Chromium browsers
3 months ago
Microsoft says it improved the contrast of text rendered in all Chromium-based web browsers on Windows, making it more readable on some displays. [...]
Sergiu Gatlan
Ransomware Scum — Out For Blood: NYBCe is Latest Victim
3 months ago
Bloody hell: New York Blood Center Enterprises crippled by ransomware scrotes unknown.
The post Ransomware Scum — Out For Blood: NYBCe is Latest Victim appeared first on Security Boulevard.
Richi Jennings
CVE-2025-22994 | O2OA 9.1.3 Meetings Setting cross site scripting (Issue 167)
3 months ago
A vulnerability was found in O2OA 9.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Meetings Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-22994. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53537 | OpenPanel up to 0.3.4 File Manager path traversal
3 months ago
A vulnerability has been found in OpenPanel up to 0.3.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the component File Manager. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-53537. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53582 | OpenPanel 0.3.4 File Manager path traversal
3 months ago
A vulnerability, which was classified as critical, was found in OpenPanel 0.3.4. Affected is an unknown function of the component File Manager. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2024-53582. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53584 | OpenPanel 0.3.4 timezone os command injection
3 months ago
A vulnerability, which was classified as critical, has been found in OpenPanel 0.3.4. This issue affects some unknown processing. The manipulation of the argument timezone leads to os command injection.
The identification of this vulnerability is CVE-2024-53584. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-53319 | Qualisys C++ SDK a32a21a XML Text Escaping Component stack-based overflow (Issue 49)
3 months ago
A vulnerability classified as problematic was found in Qualisys C++ SDK a32a21a. This vulnerability affects unknown code of the component XML Text Escaping Component. The manipulation leads to stack-based buffer overflow.
This vulnerability was named CVE-2024-53319. Access to the local network is required for this attack. There is no exploit available.
vuldb.com