Aggregator
CVE-2022-32870 | Apple watchOS Call History state issue
CVE-2020-10797 | pfSense up to 2.4.4 diag_ping.php Hostname cross site scripting
CVE-2020-11024 | Moonlight up to 4.0.0 on iOS/tvOS channel accessible
CVE-2020-11022 | jQuery up to 3.4.x html cross site scripting (ID 162159 / EDB-49766)
CVE-2020-11023 | jQuery up to 3.4.x html cross site scripting (ID 162160 / EDB-49767)
CVE-2020-12462 | ninja-forms Plugin up to 3.4.24.1 on WordPress cross-site request forgery
52款APP(SDK)被要求整改!存在侵害用户权益行为
苹果“AirBorne”漏洞可能导致零点击 AirPlay RCE 攻击
52款APP(SDK)被要求整改!存在侵害用户权益行为
苹果“AirBorne”漏洞可能导致零点击 AirPlay RCE 攻击
Windows Deployment Services Hit by 0-Click UDP Flaw Leading to System Failures
A newly discovered pre-authentication denial-of-service (DoS) vulnerability in Microsoft’s Windows Deployment Services (WDS) exposes enterprise networks to instant system crashes via malicious UDP packets. Dubbed a “0-click” flaw, attackers can exploit it remotely without user interaction, draining server memory until critical services fail. While much attention focuses on remote code execution bugs, memory exhaustion vulnerabilities in UDP-based services like […]
The post Windows Deployment Services Hit by 0-Click UDP Flaw Leading to System Failures appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Critical Microsoft 0-Click Telnet Vulnerability Enables Credential Theft Without User Action
A critical vulnerability has been uncovered in Microsoft’s Telnet Client (telnet.exe), enabling attackers to steal Windows credentials from unsuspecting users, even without interaction in certain network scenarios. Security researchers warn that this “zero-click” flaw could be readily exploited in corporate environments, with severe consequences for network integrity. How the Attack Works The vulnerability centers on […]
The post Critical Microsoft 0-Click Telnet Vulnerability Enables Credential Theft Without User Action appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.