Aggregator
.NET 安全攻防知识交流社区
4 months 1 week ago
.NET内网实战:通过winlogon进程提升至SYSTEM权限
4 months 1 week ago
CVE-2014-6284 | SAP Adaptive Server Enterprise up to 15.7/16.0 Challenge Response Mechanism access control (ID 2113995 / ID 19973)
4 months 1 week ago
A vulnerability, which was classified as critical, was found in SAP Adaptive Server Enterprise up to 15.7/16.0. This affects an unknown part of the component Challenge Response Mechanism. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2014-6284. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-6288 | Alex Kellner Powermail Extension up to 2.0.10 on TYPO3 Captcha access control (ID 11595)
4 months 1 week ago
A vulnerability was found in Alex Kellner Powermail Extension up to 2.0.10 on TYPO3 and classified as critical. This issue affects some unknown processing of the component Captcha. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2014-6288. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-6289 | Daniel Lienert Yet Another Gallery prior 3.0.0 Access Restriction access control (ID 11594)
4 months 1 week ago
A vulnerability was found in Daniel Lienert Yet Another Gallery. It has been classified as critical. Affected is an unknown function of the component Access Restriction. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2014-6289. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-6290 | News Extension up to 3.5.1 on TYPO3 input validation (ID 11508 / SBV-52333)
4 months 1 week ago
A vulnerability was found in News Extension up to 3.5.1 on TYPO3. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2014-6290. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-6293 | Statistics Extension 1.1.1 on TYPO3 sql injection (ID 11506 / SBV-52332)
4 months 1 week ago
A vulnerability classified as critical was found in Statistics Extension 1.1.1 on TYPO3. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability was named CVE-2014-6293. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2002-1570 | net-snmp/ucd-snmp PDU Message memory corruption (EDB-21200 / XFDB-7776)
4 months 1 week ago
A vulnerability classified as critical was found in net-snmp and ucd-snmp. This vulnerability affects unknown code of the component PDU Message Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2002-1570. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2000-0295 | LCDProc 0.4 screen_add memory corruption (EDB-19868 / Nessus ID 10378)
4 months 1 week ago
A vulnerability was found in LCDProc 0.4 and classified as very critical. Affected by this issue is the function screen_add. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2000-0295. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2001-0553 | SSH 3.0.0 on Unix Password Authentication privileges management (VU#737451 / Nessus ID 10708)
4 months 1 week ago
A vulnerability classified as critical was found in SSH 3.0.0 on Unix. This vulnerability affects unknown code of the component Password Authentication. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2001-0553. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2001-0549 | Symantec LiveUpdate 1.5 Password Storage cleartext storage (VU#814187 / XFDB-7013)
4 months 1 week ago
A vulnerability classified as problematic has been found in Symantec LiveUpdate 1.5. This affects an unknown part of the component Password Storage. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is uniquely identified as CVE-2001-0549. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2009-4656 | E-soft.co DJ Studio Pro 4.2 memory corruption (EDB-18501 / XFDB-53310)
4 months 1 week ago
A vulnerability was found in E-soft.co DJ Studio Pro 4.2. It has been declared as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2009-4656. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2001-0379 | HP HP-UX 11.11 newgrp privileges management (VU#249224 / XFDB-6282)
4 months 1 week ago
A vulnerability was found in HP HP-UX 11.11. It has been classified as problematic. Affected is an unknown function of the file newgrp. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2001-0379. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2001-0529 | OpenBSD OpenSSH 2.9 X Forwarding symlink (VU#655259 / Nessus ID 44071)
4 months 1 week ago
A vulnerability has been found in OpenBSD OpenSSH 2.9 and classified as critical. This vulnerability affects unknown code of the component X Forwarding Handler. The manipulation leads to symlink following.
This vulnerability was named CVE-2001-0529. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2001-0513 | Oracle9i on Win NT denial of service (VU#105259 / XFDB-6717)
4 months 1 week ago
A vulnerability was found in Oracle9i on Win NT and classified as problematic. This issue affects some unknown processing. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2001-0513. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2009-3449 | Collectorz MP3 Collector 2.3 denial of service (EDB-9689)
4 months 1 week ago
A vulnerability, which was classified as problematic, was found in Collectorz MP3 Collector 2.3. Affected is an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2009-3449. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-3660 | eFront up to 3.5.4 Libraries path code injection (EDB-9681 / BID-36411)
4 months 1 week ago
A vulnerability was found in eFront up to 3.5.4. It has been classified as critical. Affected is an unknown function of the component Libraries. The manipulation of the argument path leads to code injection.
This vulnerability is traded as CVE-2009-3660. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-3863 | Novell Groupwise 7.0.3.1294 ActiveX Control gxmim1.dll memory corruption (EDB-9683 / XFDB-53299)
4 months 1 week ago
A vulnerability was found in Novell Groupwise 7.0.3.1294. It has been declared as critical. This vulnerability affects unknown code in the library gxmim1.dll of the component ActiveX Control. The manipulation leads to memory corruption.
This vulnerability was named CVE-2009-3863. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2001-0331 | SGI IRIX 6.5.5/6.5.8 Embedded Support Partner Daemon rpc.espd memory corruption (VU#258632 / XFDB-6502)
4 months 1 week ago
A vulnerability, which was classified as critical, was found in SGI IRIX 6.5.5/6.5.8. This affects an unknown part of the file rpc.espd of the component Embedded Support Partner Daemon. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2001-0331. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com