Aggregator
CVE-2025-21994 | Linux Kernel up to 6.1.131/6.6.84/6.12.20/6.13.8 ksmbd parse_dcal num_aces allocation of resources
1 year ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.131/6.6.84/6.12.20/6.13.8. This vulnerability affects the function parse_dcal of the component ksmbd. The manipulation of the argument num_aces leads to allocation of resources.
This vulnerability was named CVE-2025-21994. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50597 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Component HTTP Server nxd_http_server.c integer underflow (TALOS-2024-2103)
1 year ago
A vulnerability classified as problematic has been found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. This affects an unknown part of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Duo Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is uniquely identified as CVE-2024-50597. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50596 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Web Component HTTP Server nx_web_http_server.c integer underflow (TALOS-2024-2103)
1 year ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Duo Web Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is handled as CVE-2024-50596. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50595 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Component HTTP Server nxd_http_server.c integer underflow (TALOS-2024-2102)
1 year ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Duo Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is known as CVE-2024-50595. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50594 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Web Component HTTP Server nx_web_http_server.c integer underflow (TALOS-2024-2102)
1 year ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been classified as problematic. Affected is an unknown function of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Duo Web Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is traded as CVE-2024-50594. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50385 | STMicroelectronics X-CUBE-AZRT-H7RS NetX Component HTTP Server nxd_http_server.c cleanup (TALOS-2024-2097)
1 year ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL and classified as critical. This issue affects some unknown processing of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Component HTTP Server. The manipulation leads to incomplete cleanup.
The identification of this vulnerability is CVE-2024-50385. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50384 | STMicroelectronics X-CUBE-AZRT-H7RS NetX Component HTTP Server nx_web_http_server.c cleanup (TALOS-2024-2097)
1 year ago
A vulnerability has been found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL and classified as critical. This vulnerability affects unknown code of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Component HTTP Server. The manipulation leads to incomplete cleanup.
This vulnerability was named CVE-2024-50384. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45064 | STMicroelectronics X-CUBE-AZRT-H7RS FileX Internal RAM Interface memory corruption (TALOS-2024-2096)
1 year ago
A vulnerability, which was classified as critical, was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL. This affects an unknown part of the component FileX Internal RAM Interface. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-45064. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
注意!HijackLoader 新增模块,恶意隐匿与反制分析能力大幅增强
1 year ago
安全客
CVE-2025-3123 | WonderCMS 3.5.0 Theme Installation/Plugin Installation installUpdateModuleAction unrestricted upload (Issue 330)
1 year ago
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme Installation/Plugin Installation. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-3123. The attack may be launched remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
The vendor explains, that "[t]he philosophy has always been, admin [...] bear responsibility to not install themes/plugins from untrusted sources."
vuldb.com
Police shuts down KidFlix child sexual exploitation platform
1 year ago
Kidflix, one of the largest platforms used to host, share, and stream child sexual abuse material (CSAM) on the dark web, was shut down on March 11 following a joint action coordinated by German law enforcement. [...]
Sergiu Gatlan
Akira
1 year ago
cohenido
Akira
1 year ago
cohenido
Submit #525101: WonderCMS 3.5.9 remote code execution [Accepted]
1 year ago
Submit #525101 / VDB-303014
cc1110
The Reality Behind Security Control Failures—And How to Prevent Them
1 year ago
Most orgs only discover their security controls failed after a breach. With OnDefend's continuous validation, you can test, measure, and prove your defenses work—before attackers exploit blind spots. [...]
Sponsored by OnDefend
How an Interdiction Mindset Can Help Win War on Cyberattacks
1 year ago
The US military and law enforcement learned to outthink insurgents. It's time for cybersecurity to learn to outsmart and outmaneuver threat actors with the same framework.
Mike McNerney
Counterfeit Android devices found preloaded with Triada malware
1 year ago
A new version of the Triada trojan has been discovered preinstalled on thousands of new Android devices, allowing threat actors to steal data as soon as they are set up. [...]
Bill Toulas
Vulnerability impacting CrushFTP
1 year ago
Canadian Centre for Cyber Security
Steam возглавил рейтинг брендов-приманок для фишеров в 2025 году
1 year ago
Миллионы геймеров получают фальшивые уведомления, ведущие к краже данных.