Aggregator
dotNet安全矩阵祝大伙 2025 年元旦快乐!
8 months ago
An announcement from Paris on Dread
8 months ago
An announcement from Paris on Dread
Dark Web Informer - Cyber Threat Intelligence
CVE-2023-21776 | Microsoft Windows up to Server 2022 Kernel information disclosure
8 months ago
A vulnerability, which was classified as problematic, was found in Microsoft Windows. This affects an unknown part of the component Kernel. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2023-21776. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-21775 | Microsoft Edge Remote Code Execution
8 months ago
A vulnerability classified as problematic was found in Microsoft Edge. This vulnerability affects unknown code. The manipulation leads to Remote Code Execution.
This vulnerability was named CVE-2023-21775. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-21796 | Microsoft Edge Remote Code Execution
8 months ago
A vulnerability, which was classified as problematic, has been found in Microsoft Edge. This issue affects some unknown processing. The manipulation leads to Remote Code Execution.
The identification of this vulnerability is CVE-2023-21796. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-23408 | Microsoft Azure HDInsights Apache Ambari cross site scripting (EDB-51546)
8 months ago
A vulnerability was found in Microsoft Azure HDInsights and classified as problematic. This issue affects some unknown processing of the component Apache Ambari. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2023-23408. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-28261 | Microsoft Edge Local Privilege Escalation
8 months ago
A vulnerability was found in Microsoft Edge. It has been classified as problematic. Affected is an unknown function. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2023-28261. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-1999-1432 | Sun Solaris 2.4/2.5/2.5.1/2.6 Power Management improper authentication (EDB-19126 / BID-160)
8 months ago
A vulnerability classified as critical has been found in Sun Solaris 2.4/2.5/2.5.1/2.6. Affected is an unknown function of the component Power Management. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-1999-1432. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
InForSec恭祝网络安全华人学者新年快乐!
8 months ago
岁月不居,时光如流。InForSec恭祝网络安全华人学者新年快乐,万事胜意!
InForSec恭祝网络安全华人学者新年快乐!
8 months ago
CVE-2000-0405 | @stake AntiSniff 1.0.1 DNS Response memory corruption (EDB-19916 / XFDB-4459)
8 months ago
A vulnerability classified as very critical was found in @stake AntiSniff 1.0.1. This vulnerability affects unknown code of the component DNS Response Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2000-0405. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Encoders
8 months ago
CVE-2006-0354 | Cisco Aironet Wireless Access ARP resource management (EDB-1447 / XFDB-24086)
8 months ago
A vulnerability was found in Cisco Aironet Wireless Access and classified as critical. Affected by this issue is some unknown functionality of the component ARP Handler. The manipulation leads to improper resource management.
This vulnerability is handled as CVE-2006-0354. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2011-5045 | Jjwdesign PHP Booking Calendar 10e details_view.php page_info_message cross site scripting (EDB-36468 / XFDB-71883)
8 months ago
A vulnerability classified as problematic was found in Jjwdesign PHP Booking Calendar 10e. This vulnerability affects unknown code of the file details_view.php. The manipulation of the argument page_info_message leads to cross site scripting.
This vulnerability was named CVE-2011-5045. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
2025元旦快乐!
8 months ago
2025元旦快乐!
8 months ago
Addressing Gen AI Privacy, Security Governance in Healthcare
8 months ago
As healthcare entities embrace generative AI tools, it's critical they take a holistic approach addressing privacy and security governance, said Dave Perry, digital workspace operations manager, St. Joseph's Healthcare in Ontario, who discusses how his organization is tackling those challenges.
Arrest of US Army Soldier Tied to AT&T and Verizon Extortion
8 months ago
Cameron Wagenius Suspected of Extorting Snowflake Customers Over Stolen Data
A serving member of the U.S. Army has been arrested on a two-count indictment tied to the theft and sale of "confidential phone records," reportedly tied to the theft of terabytes of data from AT&T, Verizon and other customers of cloud data warehousing platform Snowflake.
A serving member of the U.S. Army has been arrested on a two-count indictment tied to the theft and sale of "confidential phone records," reportedly tied to the theft of terabytes of data from AT&T, Verizon and other customers of cloud data warehousing platform Snowflake.
Safety Concerns, Pushback Against OpenAI's For-Profit Plan
8 months ago
Opponents Say Restructuring Will Undermine OpenAI's Security Commitments
OpenAI's attempt to convert to a for-profit company is facing opposition from competitors and artificial intelligence safety activists, who argue that the transition would "undermine" the tech giant's commitment to secure AI development and deployment.
OpenAI's attempt to convert to a for-profit company is facing opposition from competitors and artificial intelligence safety activists, who argue that the transition would "undermine" the tech giant's commitment to secure AI development and deployment.