Aggregator
New FASTCash malware Linux variant helps steal money from ATMs
11 months 1 week ago
error code: 1106
CVE-2024-9944 | WooCommerce Plugin up to 9.0.2 on WordPress cross site scripting
11 months 1 week ago
A vulnerability, which was classified as problematic, has been found in WooCommerce Plugin up to 9.0.2 on WordPress. This issue affects some unknown processing. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2024-9944. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Splunk Enterprise Vulnerabilities let Attackers Execute Remote Code
11 months 1 week ago
Splunk has disclosed multiple vulnerabilities affecting its Enterprise product, which could allow attackers to execute remote code. These vulnerabilities, primarily affecting Windows installations, highlight the critical need for organizations to update and secure their systems promptly. Overview of the Security Advisories Splunk, a leading provider of data analytics and monitoring solutions, has released a series […]
The post Splunk Enterprise Vulnerabilities let Attackers Execute Remote Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Divya
聚焦企业软件供应链安全防护与治理 | FCIS 2024议题前瞻
11 months 1 week ago
数字化时代,随着业务的不断转型,如何保障软件供应链安全已成为行业重点关注方向。
宝可梦游戏开发商(Game Freak)遭遇数据泄露
11 months 1 week ago
日本游戏开发商Game Freak,即《精灵宝可梦》系列游戏的幕后公司,遭遇了漏洞攻击,导致2606名员工及合作伙伴的数据外泄。 10月初,宝可梦泄漏事件的信息首次出现在“4chan”论坛上,现以“TeraLeak”的名义在社交媒体和在线论坛上流传。事件的命名效仿了2020年的“GigaLeak”任天堂泄露事件。 Centro LEAKS(对宝可梦泄漏信息进行监测的社媒账户)称:“TeraLeak包含数千兆字节的信息。” 据悉,泄露的信息中包括多条有关电子游戏的内幕消息,比如任天堂Switch 2的疑似代号、宝可梦HeartGold和SoulSilvethe等现有游戏的源代码、下一代《口袋妖怪》游戏的数据以及一款尚未公布的游戏名称。 Game Freak确认漏洞 10月10日,游戏公司证实,它在8月的确经历了一起安全事件,在此期间,第三方未经授权访问了其系统,导致了2606名前、现任员工信息的泄露。 Game Freak表示:“我们已经检查并重建了服务器,将进一步加强安全措施,防止泄露的再次发生。另外,我们正在单独联系受到影响的员工,并专设事件热线,处理有关此事的查询。” 至于宝可梦或任天堂相关的数据是否被曝光,该公司并未说明,也未披露泄露信息的准确性。 即将推出的宝可梦游戏《宝可梦传奇:Z-A》目前正在开发中,计划于2025年发布。 消息来源:Infosecurity-Magazine,译者:XX; 本文由 HackerNews.cc 翻译整理,封面来源于网络; 转载请注明“转自 HackerNews.cc”并附上原文
hackernews
Alleged Cisco Breach Exposes Sensitive Data from Major Companies, According to Attackers on Deep Web
11 months 1 week ago
cohenido
CVE-2016-1350 | Cisco Unified Communications Manager 15.3/15.4 SIP Message resource management (CSCuj23293 / Nessus ID 90310)
11 months 1 week ago
A vulnerability, which was classified as critical, has been found in Cisco Unified Communications Manager 15.3/15.4. This issue affects some unknown processing of the component SIP Message Handler. The manipulation leads to improper resource management.
The identification of this vulnerability is CVE-2016-1350. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
Тень OilRig: Иран наносит удар по инфраструктуре ОАЭ
11 months 1 week ago
CVE-2024-30088 позволяет злоумышленникам красть данные через STEALHOOK.
CVE-2024-9977 | MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26 Firewall Settings Page settings-firewall.cgi SrcInterface os command injection
11 months 1 week ago
A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected is an unknown function of the file /cgi-bin/settings-firewall.cgi of the component Firewall Settings Page. The manipulation of the argument SrcInterface leads to os command injection.
This vulnerability is traded as CVE-2024-9977. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
vuldb.com
CVE-2024-0129 | NVIDIA NeMo up to All versions r2.0.0rc0 Tar File Extraction SaveRestoreConnector path traversal
11 months 1 week ago
A vulnerability, which was classified as critical, has been found in NVIDIA NeMo up to All versions r2.0.0rc0. This issue affects the function SaveRestoreConnector of the component Tar File Extraction Handler. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-0129. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #423561: Mitrastar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26 OS Command Injection [Accepted]
11 months 1 week ago
Submit #423561 / VDB-280344
peritocibernetico
Дыры в E2EE: как хакеры «меняют замки» в вашем облачном хранилище
11 months 1 week ago
22 миллиона пользователей рискуют потерять свои данные из-за недостатков безопасности сервисов.
CVE-2022-36033 | jsoup up to 1.15.2 javascript URL cross site scripting (GHSA-gp7f-rwcx-9369 / Nessus ID 209012)
11 months 1 week ago
A vulnerability was found in jsoup up to 1.15.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component javascript URL Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2022-36033. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-36033 | Oracle Communications Cloud Native Core Console 22.2.0 Installer cross site scripting (Nessus ID 209012)
11 months 1 week ago
A vulnerability was found in Oracle Communications Cloud Native Core Console 22.2.0. It has been classified as critical. Affected is an unknown function of the component Installer. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2022-36033. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-36033 | Oracle Financial Services Crime and Compliance Management Studio cross site scripting (Nessus ID 209012)
11 months 1 week ago
A vulnerability was found in Oracle Financial Services Crime and Compliance Management Studio 8.0.8.3.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Studio. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2022-36033. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-34169 | Oracle Financial Services Enterprise Case Management 8.0.8.2/8.1.1.1/8.1.2.5/8.1.2.6 Web UI numeric conversion (Nessus ID 209012)
11 months 1 week ago
A vulnerability was found in Oracle Financial Services Enterprise Case Management 8.0.8.2/8.1.1.1/8.1.2.5/8.1.2.6. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Web UI. The manipulation leads to incorrect conversion between numeric types.
This vulnerability is known as CVE-2022-34169. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-34169 | Oracle Agile PLM 9.3.6 Application Server numeric conversion (Nessus ID 209012)
11 months 1 week ago
A vulnerability, which was classified as critical, has been found in Oracle Agile PLM 9.3.6. This issue affects some unknown processing of the component Application Server. The manipulation leads to incorrect conversion between numeric types.
The identification of this vulnerability is CVE-2022-34169. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-34169 | Oracle Financial Services Revenue Management and Billing up to 4.0 Infrastructure numeric conversion (Nessus ID 209012)
11 months 1 week ago
A vulnerability was found in Oracle Financial Services Revenue Management and Billing up to 4.0. It has been classified as critical. Affected is an unknown function of the component Infrastructure. The manipulation leads to incorrect conversion between numeric types.
This vulnerability is traded as CVE-2022-34169. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-34169 | Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 JAXP numeric conversion (Nessus ID 209012)
11 months 1 week ago
A vulnerability classified as critical has been found in Oracle Business Intelligence Enterprise Edition 12.2.1.4.0. Affected is an unknown function of the component JAXP. The manipulation leads to incorrect conversion between numeric types.
This vulnerability is traded as CVE-2022-34169. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com