Aggregator
Бюджетные IT-гуру: почему низкие расценки фрилансеров должны настораживать работодателей
4 months ago
Немецкие спецслужбы раскрывают международную сеть IT-мошенников.
CVE-2020-16040 | Google Chrome up to 87.0.4280.66 V8 Remote Code Execution (EDB-49745)
4 months ago
A vulnerability classified as critical has been found in Google Chrome. Affected is an unknown function of the component V8. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2020-16040. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
ChatGPT 推出编程专用界面;特斯拉美国停售 Model 3 标续后驱版;问界针对 BBA 门店制定「特别计划」|极客早知道
4 months ago
OpenAI推出专为写作和编程项目定制的新 ChatGPT 界面10 月 3 日,OpenAI 推出了一种与 ChatGPT 交互的新方式:一种被称为「画布」的界面。该产品会在正常聊天窗口旁打开一个单
CVE-2024-9410 | Ada Support Ada.cx Sentry Component prior October 1/2024 Configuration server-side request forgery
4 months ago
A vulnerability has been found in Ada Support Ada.cx Sentry Component and classified as critical. Affected by this vulnerability is an unknown functionality of the component Configuration Handler. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2024-9410. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47790 | D3D Security IP Camera D8801 Real-Time Streaming Protocol authorization (CIVN-2024-0314)
4 months ago
A vulnerability, which was classified as problematic, was found in D3D Security IP Camera D8801. Affected is an unknown function of the component Real-Time Streaming Protocol Handler. The manipulation leads to missing authorization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2024-47790. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-47789 | D3D Security IP Camera D8801 HTTP Header Protocol cleartext transmission (CIVN-2024-0314)
4 months ago
A vulnerability, which was classified as problematic, has been found in D3D Security IP Camera D8801. This issue affects some unknown processing of the component HTTP Header Protocol Handler. The manipulation leads to cleartext transmission of sensitive information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-47789. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9484 | AVG/Avast Antivirus 24.1 on macOS Engine Module null pointer dereference
4 months ago
A vulnerability classified as problematic was found in AVG/Avast Antivirus 24.1 on macOS. This vulnerability affects unknown code of the component Engine Module. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-9484. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Cybersecurity Is Serious — but It Doesn't Have to Be Boring
4 months ago
Thoughtfully applied, humor breaks through security fatigue, increases engagement, and fosters a culture of security awareness.
Akhil Mittal
SonarQube 10.7 Release Announcement
4 months ago
Sonar introduces powerful AI-driven features, expanded support for new and existing languages and frameworks, and deeper security, all to elevate your code quality. These updates bring significant advancements for developers and teams.
The post SonarQube 10.7 Release Announcement appeared first on Security Boulevard.
Robert Curlee
How Confidence Between Teams Impacts Cyber Incident Outcomes
4 months ago
Infosecurity recently joined an Immersive Labs Cyber Drill to experience how organizations can enhance their preparedness through training and simulations
CVE-2024-9483 | AVG/Avast Antivirus 24.1 on macOS Signature Verification Module null pointer dereference
4 months ago
A vulnerability classified as problematic has been found in AVG/Avast Antivirus 24.1 on macOS. This affects an unknown part of the component Signature Verification Module. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2024-9483. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47657 | Shilpi Computers Net Back Office API Endpoint authorization (CIVN-2024-0313)
4 months ago
A vulnerability was found in Shilpi Computers Net Back Office. It has been rated as problematic. Affected by this issue is some unknown functionality of the component API Endpoint. The manipulation leads to authorization bypass.
This vulnerability is handled as CVE-2024-47657. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-22119 | Zabbix up to 5.0.39/6.0.23/6.4.8/7.0.0alpha7 Graph Page Name input validation (Nessus ID 208100)
4 months ago
A vulnerability, which was classified as problematic, has been found in Zabbix up to 5.0.39/6.0.23/6.4.8/7.0.0alpha7. This issue affects some unknown processing of the component Graph Page. The manipulation of the argument Name leads to improper input validation.
The identification of this vulnerability is CVE-2024-22119. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22116 | Zabbix up to 6.4.15/7.0.0rc2 Monitoring Hosts Section code injection (Nessus ID 208100)
4 months ago
A vulnerability has been found in Zabbix up to 6.4.15/7.0.0rc2 and classified as critical. This vulnerability affects unknown code of the component Monitoring Hosts Section. The manipulation leads to code injection.
This vulnerability was named CVE-2024-22116. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-32722 | Zabbix zbxjson zbx_json_open buffer overflow (Nessus ID 208100)
4 months ago
A vulnerability was found in Zabbix and classified as critical. This issue affects the function zbx_json_open of the component zbxjson. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2023-32722. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-32724 | Zabbix Ducktape Object permission assignment (Nessus ID 208100)
4 months ago
A vulnerability was found in Zabbix. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Ducktape Object Handler. The manipulation leads to incorrect permission assignment.
This vulnerability is known as CVE-2023-32724. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-32726 | Zabbix up to 5.0.39/6.0.23/6.4.8/7.0.0alpha7 DNS Response unusual condition (Nessus ID 208100)
4 months ago
A vulnerability was found in Zabbix up to 5.0.39/6.0.23/6.4.8/7.0.0alpha7. It has been rated as problematic. This issue affects some unknown processing of the component DNS Response Handler. The manipulation leads to improper check for unusual conditions.
The identification of this vulnerability is CVE-2023-32726. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-32727 | Zabbix up to 4.0.49/5.0.38/6.0.22/6.4.7/7.0.0alpha6 icmpping input validation (Nessus ID 208100)
4 months ago
A vulnerability classified as problematic was found in Zabbix up to 4.0.49/5.0.38/6.0.22/6.4.7/7.0.0alpha6. Affected by this vulnerability is the function icmpping. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2023-32727. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22114 | Zabbix up to 5.0.42/6.0.30/6.4.15/7.0.0rc2 System Information Widget permissions (Nessus ID 208100)
4 months ago
A vulnerability was found in Zabbix up to 5.0.42/6.0.30/6.4.15/7.0.0rc2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component System Information Widget. The manipulation leads to preservation of permissions.
This vulnerability is known as CVE-2024-22114. The attack can be launched remotely. There is no exploit available.
vuldb.com