Aggregator
《网络空间安全科学学报》2024年网络空间安全学术会议顺利召开
2 weeks 5 days ago
五种用来挖掘API端点的方法
2 weeks 5 days ago
声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由用户承担全部法
CVE-2023-49100 | Trusted Firmware-A up to 2.9 SDEI Service sdei_interrupt_bind out-of-bounds
2 weeks 5 days ago
A vulnerability was found in Trusted Firmware-A up to 2.9. It has been classified as problematic. Affected is the function sdei_interrupt_bind of the component SDEI Service. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2023-49100. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27279 | Appleple A-Blog CMS path traversal
2 weeks 5 days ago
A vulnerability, which was classified as critical, has been found in Appleple A-Blog CMS. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-27279. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-24093 | code-projects Scholars Tracking System 1.0 Personal Information Update sql injection
2 weeks 5 days ago
A vulnerability was found in code-projects Scholars Tracking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component Personal Information Update. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-24093. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-43279 | tcpreplay 4.4.4 Tcprewrite cidr.c mask_cidr6 null pointer dereference (Issue 824)
2 weeks 5 days ago
A vulnerability was found in tcpreplay 4.4.4. It has been rated as problematic. This issue affects the function mask_cidr6 of the file cidr.c of the component Tcprewrite Handler. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2023-43279. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-52613 | Linux Kernel up to 6.6.13/6.7.1 loongson2_thermal PTR_ERR comparison (70481755ed77/6010a9fc14eb/15ef92e9c411)
2 weeks 5 days ago
A vulnerability was found in Linux Kernel up to 6.6.13/6.7.1 and classified as problematic. Affected by this issue is the function PTR_ERR of the component loongson2_thermal. The manipulation leads to incorrect comparison.
This vulnerability is handled as CVE-2023-52613. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-28303 | Open Source Medicine Ordering System 1.0 /admin/reports/index.php date sql injection
2 weeks 5 days ago
A vulnerability classified as critical was found in Open Source Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reports/index.php. The manipulation of the argument date leads to sql injection.
This vulnerability is known as CVE-2024-28303. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-21099 | Oracle Business Intelligence Enterprise Edition 7.0.0.0.0 Data Visualization information disclosure
2 weeks 5 days ago
A vulnerability has been found in Oracle Business Intelligence Enterprise Edition 7.0.0.0.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Data Visualization. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-21099. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35989 | Linux Kernel up to 5.15.157/6.1.89/6.6.29/6.8.8 dmaengine memory corruption (Nessus ID 207773)
2 weeks 5 days ago
A vulnerability was found in Linux Kernel up to 5.15.157/6.1.89/6.6.29/6.8.8. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component dmaengine. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2024-35989. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52704 | Linux Kernel up to 6.1.12 freezer call_usermode_helper_exec denial of service (7f9f6c54da87/eedeb787ebb5)
2 weeks 5 days ago
A vulnerability was found in Linux Kernel up to 6.1.12. It has been rated as critical. Affected by this issue is the function call_usermode_helper_exec of the component freezer. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2023-52704. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35958 | Linux Kernel up to 5.10.215/5.15.155/6.1.86/6.6.27/6.8.6 ena_free_tx_bufs use after free (Nessus ID 209785)
2 weeks 5 days ago
A vulnerability classified as problematic was found in Linux Kernel up to 5.10.215/5.15.155/6.1.86/6.6.27/6.8.6. Affected by this vulnerability is the function ena_free_tx_bufs. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-35958. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2403 | Apple macOS up to 10.12.3 Printing format string (HT207615 / Nessus ID 99134)
2 weeks 5 days ago
A vulnerability was found in Apple macOS up to 10.12.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component Printing. The manipulation leads to format string.
This vulnerability is handled as CVE-2017-2403. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
万圣节,一起 Cozeplay ! iPhone 16 Pro Max、Switch、扣子周边等500份“糖果”掉落!
2 weeks 5 days ago
Max、Switch、扣子周边等500份“糖果“掉.扫码生成你的万圣限定风格照 分亨还能二次抽奖!
AI 代码编程助手真的有用吗
2 weeks 5 days ago
AI 代码编程助手的出现,标志着编程方式可能迎来一次重大革新。这种新兴技术不仅引起了开发者的广泛关注,也值得所有对科技发展感兴趣的人深入了解。
CVE-2016-4328 | MEDHOST Perioperative Information Management System prior 2015R1 hard-coded credentials (VU#482135)
2 weeks 5 days ago
A vulnerability was found in MEDHOST Perioperative Information Management System. It has been classified as problematic. This affects an unknown part. The manipulation leads to hard-coded credentials.
This vulnerability is uniquely identified as CVE-2016-4328. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
888 Has Allegedly Leaked the Database of Ensinio
2 weeks 5 days ago
888 Has Allegedly Leaked the Database of Ensinio
Dark Web Informer
303 is Allegedly Selling Unauthorized Access to Asus Taiwan
2 weeks 5 days ago
303 is Allegedly Selling Unauthorized Access to Asus Taiwan
Dark Web Informer
CVE-2012-1182 | Samba up to 3.6.x ndr_pull_dfs_Info3 numeric error (ZDI-12-061 / EDB-21850)
2 weeks 5 days ago
A vulnerability, which was classified as very critical, was found in Samba up to 3.6.x. This affects the function ndr_pull_dfs_Info3. The manipulation leads to numeric error.
This vulnerability is uniquely identified as CVE-2012-1182. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com