Aggregator
CVE-2012-1182 | Samba up to 3.6.x NDR PULL LSA TrustDomainInfoControllers numeric error (ZDI-12-062 / EDB-21850)
2 weeks 5 days ago
A vulnerability has been found in Samba up to 3.6.x and classified as very critical. This vulnerability affects the function TrustDomainInfoControllers of the component NDR PULL LSA. The manipulation leads to numeric error.
This vulnerability was named CVE-2012-1182. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
书生大模型实战营闯关 第四关 玩转Hugging Face
2 weeks 5 days ago
CVE-2010-0167 | Mozilla Firefox up to 3.6 Browser Engine _evaluate memory corruption (MFSA2010-11 / EDB-33801)
2 weeks 5 days ago
A vulnerability was found in Mozilla Firefox. It has been rated as very critical. This issue affects the function _evaluate of the component Browser Engine. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2010-0167. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
How Doppler aligns with your SPACE framework
2 weeks 5 days ago
What is the SPACE Framework? See how Doppler’s features improve your team’s wellbeing, efficiency, and secrets management posture
The post How Doppler aligns with your SPACE framework appeared first on Security Boulevard.
Dylan Villeneuve
CVE-2023-2062 | Mitsubishi Electric MELSEC iQ-R missing password field masking
2 weeks 5 days ago
A vulnerability classified as problematic was found in Mitsubishi Electric MELSEC iQ-R. This vulnerability affects unknown code. The manipulation leads to missing password field masking.
This vulnerability was named CVE-2023-2062. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-34002 | Moodle mod_feedback file inclusion
2 weeks 5 days ago
A vulnerability was found in Moodle and classified as critical. This issue affects some unknown processing of the component mod_feedback. The manipulation leads to file inclusion.
The identification of this vulnerability is CVE-2024-34002. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-31395 | Appleple A-Blog CMS up to 3.1.11 cross site scripting
2 weeks 5 days ago
A vulnerability was found in Appleple A-Blog CMS up to 3.1.11. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-31395. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47439 | Linux Kernel up to 5.10.74/5.14.13 ksz_mib_read_work null pointer dereference (f2e1de075018/383239a33cf2/ef1100ef20f2)
2 weeks 5 days ago
A vulnerability was found in Linux Kernel up to 5.10.74/5.14.13. It has been classified as critical. Affected is the function ksz_mib_read_work. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2021-47439. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47471 | Linux Kernel up to 5.10.75/5.14.14 mxsfb_irq_disable null pointer dereference (f40c2281d2c0/b0e6db0656dd/3cfc183052c3)
2 weeks 5 days ago
A vulnerability was found in Linux Kernel up to 5.10.75/5.14.14. It has been declared as critical. This vulnerability affects the function mxsfb_irq_disable. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2021-47471. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5143 | HP LaserJet Pro Printer SMTP Server Setting improper authentication
2 weeks 5 days ago
A vulnerability was found in HP LaserJet Pro Printer. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SMTP Server Setting Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-5143. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2024-33470 | AVTECH Room Alert 4E 4.4.0 SMTP Email Setting missing encryption
2 weeks 5 days ago
A vulnerability was found in AVTECH Room Alert 4E 4.4.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component SMTP Email Setting Handler. The manipulation leads to missing encryption of sensitive data. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2024-33470. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-4530 | Business Card Plugin up to 1.0.0 on WordPress cross-site request forgery
2 weeks 5 days ago
A vulnerability, which was classified as problematic, was found in Business Card Plugin up to 1.0.0 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-4530. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-36036 | Zoho ManageEngine ADAudit Plus up to 7260 information disclosure
2 weeks 5 days ago
A vulnerability classified as problematic has been found in Zoho ManageEngine ADAudit Plus up to 7260. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-36036. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5498 | Google Chrome up to 125.0.6422.112 Presentation API use after free (ID 339588)
2 weeks 5 days ago
A vulnerability has been found in Google Chrome and classified as critical. Affected by this vulnerability is an unknown functionality of the component Presentation API. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-5498. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3592 | Quiz and Survey Master Plugin up to 9.0.1 on WordPress sql injection
2 weeks 5 days ago
A vulnerability, which was classified as critical, has been found in Quiz and Survey Master Plugin up to 9.0.1 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-3592. The attack may be launched remotely. There is no exploit available.
vuldb.com
Daily Dose of Dark Web Informer - October 31st, 2024
2 weeks 5 days ago
This daily article is intended to make it easier for those who want to stay updated with my regular posts. Any subscriber-only content will be clearly marked at the end of the link.
Dark Web Informer
CVE-2017-2413 | Apple macOS up to 10.12.3 QuickTime memory corruption (HT207615 / Nessus ID 99134)
2 weeks 5 days ago
A vulnerability classified as critical was found in Apple macOS up to 10.12.3. This vulnerability affects unknown code of the component QuickTime. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2413. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
abyss0 is Allegedly Selling IBM Aspera Access to an Unidentified Financial Software Company
2 weeks 5 days ago
abyss0 is Allegedly Selling IBM Aspera Access to an Unidentified Financial Software Company
Dark Web Informer
CVE-2016-4965 | Fortinet FortiWan up to 4.2.4 nslookup diagnosis_control.php graph os command injection (VU#724487 / BID-92779)
2 weeks 5 days ago
A vulnerability, which was classified as critical, has been found in Fortinet FortiWan up to 4.2.4. Affected by this issue is some unknown functionality of the file diagnosis_control.php of the component nslookup Handler. The manipulation of the argument graph leads to os command injection.
This vulnerability is handled as CVE-2016-4965. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com