Aggregator
Akira
4 months ago
cohenido
CVE-2024-41673 | Decidim up to 0.27.7 Version Control cross site scripting (GHSA-cc4g-m3g7-xmw8)
4 months ago
A vulnerability was found in Decidim up to 0.27.7 and classified as problematic. This issue affects some unknown processing of the component Version Control. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-41673. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9400 | Mozilla Firefox up to 128.2/130 JIT Compilation memory corruption (Nessus ID 207987)
4 months ago
A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 128.2/130. This affects an unknown part of the component JIT Compilation. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-9400. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9400 | Mozilla Thunderbird up to 128.2/130 JIT Compilation memory corruption (Nessus ID 207987)
4 months ago
A vulnerability has been found in Mozilla Thunderbird up to 128.2/130 and classified as critical. This vulnerability affects unknown code of the component JIT Compilation. The manipulation leads to memory corruption.
This vulnerability was named CVE-2024-9400. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47604 | NuGet Gallery up to 2024.09.25 HTML Element HTML injection
4 months ago
A vulnerability, which was classified as problematic, has been found in NuGet Gallery up to 2024.09.25. Affected by this issue is some unknown functionality of the component HTML Element Handler. The manipulation leads to HTML injection.
This vulnerability is handled as CVE-2024-47604. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47534 | theupdateframework go-tuf up to 2.0.0 race condition
4 months ago
A vulnerability classified as problematic was found in theupdateframework go-tuf up to 2.0.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to race condition.
This vulnerability is known as CVE-2024-47534. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47071 | FreePBX OSS Endpoint Manager up to 14.0.3 Module path traversal
4 months ago
A vulnerability classified as critical has been found in FreePBX OSS Endpoint Manager up to 14.0.3. Affected is an unknown function of the component Module Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2024-47071. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Hacking API discovery with a custom Burp extension
4 months ago
Learn how to improve your API discovery with a custom Burp Suite extension dedicated to automatically finding API document artifacts for you.
The post Hacking API discovery with a custom Burp extension appeared first on Dana Epp's Blog.
Dana Epp
Infrastructure vs. Runtime — Where Are Your Priorities?
4 months ago
Amid the noise of new solutions and buzzwords, understanding the balance between securing infrastructure and implementing runtime security is key to crafting an effective cloud strategy.
Han Cho
微软开始推送 Windows 11 2024 更新
4 months ago
微软宣布开始推送 Windows 11 2024 或 v24H2 更新。首先获得更新的将是运行 v22H2 或 23H2 版本的 Windows 11 PC。v24H2 的新功能包括:用节能功能替代旧的节电模式,支持 Wi-Fi 7 和 80Gbps USB4 Version 2.0 端口,受争议的 Recall 功能,改进 Windows Search,Photos 应用支持超分辨率,画图应用(Paint)加入生成填充和擦除功能,改进 Arm-to-x86 应用翻译层 Prism 的性能和兼容性,等等。
CVE-2024-9399 | Mozilla Firefox up to 128.2/130 WebTransport denial of service (Nessus ID 207987)
4 months ago
A vulnerability was found in Mozilla Firefox up to 128.2/130. It has been declared as problematic. This vulnerability affects unknown code of the component WebTransport Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-9399. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9399 | Mozilla Thunderbird up to 128.2/130 WebTransport denial of service (Nessus ID 207987)
4 months ago
A vulnerability was found in Mozilla Thunderbird up to 128.2/130. It has been rated as problematic. This issue affects some unknown processing of the component WebTransport Handler. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2024-9399. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9398 | Mozilla Thunderbird up to 128.2/130 Protocol window.open information disclosure (Nessus ID 207987)
4 months ago
A vulnerability was found in Mozilla Thunderbird up to 128.2/130. It has been classified as problematic. This affects the function window.open of the component Protocol Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-9398. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9398 | Mozilla Firefox up to 128.2/130 Protocol window.open information disclosure (Nessus ID 207987)
4 months ago
A vulnerability was found in Mozilla Firefox up to 128.2/130 and classified as problematic. Affected by this issue is the function window.open of the component Protocol Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-9398. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SecWiki News 2024-10-01 Review
4 months ago
CVE-2024-9397 | Mozilla Thunderbird up to 130 Directory Upload UI clickjacking (Nessus ID 207987)
4 months ago
A vulnerability has been found in Mozilla Thunderbird up to 130 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Directory Upload UI. The manipulation leads to clickjacking.
This vulnerability is known as CVE-2024-9397. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9397 | Mozilla Firefox up to 130 Directory Upload UI clickjacking (Nessus ID 207987)
4 months ago
A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 130. Affected is an unknown function of the component Directory Upload UI. The manipulation leads to clickjacking.
This vulnerability is traded as CVE-2024-9397. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9403 | Mozilla Firefox 130 memory corruption (Nessus ID 207987)
4 months ago
A vulnerability classified as critical was found in Mozilla Firefox 130. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2024-9403. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9403 | Mozilla Thunderbird 130 memory corruption (Nessus ID 207987)
4 months ago
A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird 130. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2024-9403. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com