Aggregator
CVE-2010-0557 | IBM Cognos Express 9.0 Hardcoded Credentials credentials management (EDB-18619 / Nessus ID 34970)
1 year 6 months ago
A vulnerability was found in IBM Cognos Express 9.0. It has been rated as critical. This issue affects some unknown processing of the component Hardcoded Credentials. The manipulation leads to credentials management.
The identification of this vulnerability is CVE-2010-0557. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2011-5099 | Chillcreations Mod Ccnewsletter up to 1.0.7 mod_ccnewsletter) id sql injection (EDB-37101 / XFDB-75112)
1 year 6 months ago
A vulnerability was found in Chillcreations Mod Ccnewsletter up to 1.0.7 and classified as critical. This issue affects some unknown processing of the component mod_ccnewsletter). The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2011-5099. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-6445 | NTPsec up to 1.1.2 ntpd ntp_control.c null pointer dereference (EDB-46177 / Nessus ID 121340)
1 year 6 months ago
A vulnerability was found in NTPsec up to 1.1.2. It has been classified as problematic. This affects an unknown part of the file ntp_control.c of the component ntpd. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2019-6445. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-36551 | Heartex Label Studio Community Edition up to 1.5.0 Import Module server-side request forgery (EDB-51109)
1 year 6 months ago
A vulnerability was found in Heartex Label Studio Community Edition up to 1.5.0. It has been classified as critical. Affected is an unknown function of the component Import Module. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-36551. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Trump’s 2024 Victory Sparks AI Policy Debate: What’s Next for America’s Tech Future?
1 year 6 months ago
As Donald Trump prepares to take office, America’s artificial intelligence (AI) policy stands at a c
特朗普重返白宫引发以色列进攻性网络安全产业剧变:NSO败诉、Paragon易主
1 year 6 months ago
特朗普2.0
CVE-2005-0468 | MIT Kerberos 5.18 Telnet Client slc_add_reply heap-based overflow (VU#341908 / EDB-25303)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in MIT Kerberos 5.18. Affected is the function slc_add_reply of the component Telnet Client. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2005-0468. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to disable the affected component.
vuldb.com
CVE-2015-8729 | Wireshark up to 1.12.8/2.0.0 Ascend File Parser wiretap/ascendtext.c ascend_seek input validation (EDB-38995 / Nessus ID 87824)
1 year 6 months ago
A vulnerability classified as problematic has been found in Wireshark up to 1.12.8/2.0.0. This affects the function ascend_seek of the file wiretap/ascendtext.c of the component Ascend File Parser. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2015-8729. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
任意账户绑定微信逻辑缺陷案例
1 year 6 months ago
01JS中发现未授权接口来自hxd lalala师傅的案例--案例已修复URL:https://job.****.***.cn/job/qrlogin登陆成功以后右上角个人信息来到微信绑定的页面通过审
任意账户绑定微信逻辑缺陷案例
1 year 6 months ago
Ig account
1 year 6 months ago
CVE-2015-8723 | Wireshark up to 1.12.8/2.0.0 802.11 Dissector epan/crypt/airpdcap.c AirPDcapPacketProcess input validation (EDB-38995 / Nessus ID 87824)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Wireshark up to 1.12.8/2.0.0. This affects the function AirPDcapPacketProcess of the file epan/crypt/airpdcap.c of the component 802.11 Dissector. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2015-8723. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-4094 | IBM Rational Test Lab Manager Default Password credentials management (EDB-18619 / Nessus ID 34970)
1 year 6 months ago
A vulnerability was found in IBM Rational Test Lab Manager. It has been rated as critical. Affected by this issue is some unknown functionality of the component Default Password. The manipulation leads to credentials management.
This vulnerability is handled as CVE-2010-4094. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.
vuldb.com
CVE-2017-15118 | QEMU NBD Server out-of-bounds write (USN-3575-2 / EDB-43194)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in QEMU. Affected is an unknown function of the component NBD Server. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2017-15118. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-31188 | CVAT up to 1.x server-side request forgery (GHSA-7vpj-j5xv-29pr / EDB-51030)
1 year 6 months ago
A vulnerability classified as critical has been found in CVAT up to 1.x. Affected is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-31188. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
这些值得一看的软件|但不一定有用[241222]
1 year 6 months ago
CVE-2000-0204 | Trend Micro OfficeScan 3.5 HTTP Connection denial of service (EDB-19780 / ID 38074)
1 year 6 months ago
A vulnerability was found in Trend Micro OfficeScan 3.5. It has been classified as problematic. Affected is an unknown function of the component HTTP Connection Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2000-0204. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
乔治城大学 | 真实网络中审查规避行为的精确检测
1 year 6 months ago
原文标题:On Precisely Detecting Censorship Circumvention in Real-World Networks原文作者:Ryan Wails, George A
乔治城大学 | 真实网络中审查规避行为的精确检测
1 year 6 months ago
提出了一种结合深度学习方法的基于主机的检测方案。