Aggregator
The State of the Virtual CISO Report: MSP/MSSP Security Strategies for 2025
1 year 6 months ago
The 2024 State of the vCISO Report continues Cynomi's tradition of examining the growing popularity
俄罗斯购买有 25 年历史 ASML 机器制造军用芯片
1 year 6 months ago
俄罗斯被发现通过中间商购买有 25 年历史的 ASML 二手机器制造军用无人机使用的芯片。ASML 是世界最先进的光刻机制造商,俄罗斯入侵乌克兰之后,欧洲禁止向其出口先进设备。ASML 表
CVE-2007-3629 | Levent Veysi Portal 1.0 oku.asp id sql injection (EDB-30282 / XFDB-35282)
1 year 6 months ago
A vulnerability classified as very critical was found in Levent Veysi Portal 1.0. This vulnerability affects unknown code of the file oku.asp. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2007-3629. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
德银 CEO 督促德国人更努力的工作
1 year 6 months ago
德银 CEO Christian Sewing 本周督促德国人更努力的工作,帮助恢复国家经济。Sewing 在法兰克福举行的德国商报(Handelsblatt)银行峰会上表示,投资者已开始
CVE-2020-24918 | Ambarella Oryx RTSP Server 2020-01-07 RTSP Request libamprotocol-rtsp.so.1 parse_authentication_header buffer overflow
1 year 6 months ago
A vulnerability was found in Ambarella Oryx RTSP Server 2020-01-07. It has been classified as critical. Affected is the function parse_authentication_header of the file libamprotocol-rtsp.so.1 of the component RTSP Request Handler. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2020-24918. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-34259 | Kyocera TASKalfa 4053ci up to 2VG_S000.002.561 Web Service path traversal
1 year 6 months ago
A vulnerability classified as critical has been found in Kyocera TASKalfa 4053ci up to 2VG_S000.002.561. This affects an unknown part of the component Web Service Handler. The manipulation leads to path traversal: '../filedir'.
This vulnerability is uniquely identified as CVE-2023-34259. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-31102 | 7-zip up to 18.03 7Z File Parser integer underflow (ZDI-23-1165)
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in 7-zip. This issue affects some unknown processing of the component 7Z File Parser. The manipulation leads to integer underflow.
The identification of this vulnerability is CVE-2023-31102. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-46817 | phpFox up to 4.8.13 Request Parameter /core/redirect unserialize url code injection
1 year 6 months ago
A vulnerability was found in phpFox up to 4.8.13. It has been declared as critical. This vulnerability affects the function unserialize of the file /core/redirect of the component Request Parameter Handler. The manipulation of the argument url leads to code injection.
This vulnerability was named CVE-2023-46817. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-45024 | Request Tracker 5.0.3/5.0.4 Transaction Search information disclosure
1 year 6 months ago
A vulnerability was found in Request Tracker 5.0.3/5.0.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Transaction Search Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-45024. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-47204 | transmute-core up to 1.13.4 YAML deserialization
1 year 6 months ago
A vulnerability classified as problematic was found in transmute-core up to 1.13.4. This vulnerability affects unknown code of the component YAML Handler. The manipulation leads to deserialization.
This vulnerability was named CVE-2023-47204. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-34259 | Kyocera TASKalfa 4053ci up to 2VG_S000.002.561 Incomplete Fix CVE-2020-23575 wlmdeu%2f%2e%2e%2f%2e%2e path traversal
1 year 6 months ago
A vulnerability classified as problematic has been found in Kyocera TASKalfa 4053ci up to 2VG_S000.002.561. Affected is an unknown function of the file /wlmdeu%2f%2e%2e%2f%2e%2e of the component Incomplete Fix CVE-2020-23575. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2023-34259. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-46352 | Smart Modules Pixel Plus Module up to 2.4.9 on PrestaShop ps_customer Table name/surname/email permission
1 year 6 months ago
A vulnerability has been found in Smart Modules Pixel Plus Module up to 2.4.9 on PrestaShop and classified as problematic. This vulnerability affects unknown code of the component ps_customer Table Handler. The manipulation of the argument name/surname/email leads to permission issues.
This vulnerability was named CVE-2023-46352. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-46958 | lmxcms 1.41 admin.php Privilege Escalation
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in lmxcms 1.41. This issue affects some unknown processing of the file admin.php. The manipulation leads to Privilege Escalation.
The identification of this vulnerability is CVE-2023-46958. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-46947 | Intelliants Subrion 4.2.1 code injection (Issue 909)
1 year 6 months ago
A vulnerability has been found in Intelliants Subrion 4.2.1 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to code injection.
This vulnerability is known as CVE-2023-46947. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-46404 | PCRS up to 3.11 Questions Page/Code Editor sandbox
1 year 6 months ago
A vulnerability was found in PCRS up to 3.11. It has been rated as critical. This issue affects some unknown processing of the component Questions Page/Code Editor. The manipulation leads to sandbox issue.
The identification of this vulnerability is CVE-2023-46404. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-46980 | Best Courier Management System 1.0 userID Privilege Escalation
1 year 6 months ago
A vulnerability classified as critical has been found in Best Courier Management System 1.0. Affected is an unknown function. The manipulation of the argument userID leads to Privilege Escalation.
This vulnerability is traded as CVE-2023-46980. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #305 – Two Full Days on Big Room Planning
1 year 6 months ago
via the respected Software Engineering expertise of Mikkel Noe-Nygaard and the lauded Software Engineering / Enterprise Agile Coaching work of Luxshan Ratnaravi at Comic Agilé!
The post Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #305 – Two Full Days on Big Room Planning appeared first on Security Boulevard.
Marc Handelman
CVE-2007-0140 | Kolayindir Download down.asp id sql injection (EDB-29385 / XFDB-31320)
1 year 6 months ago
A vulnerability classified as critical was found in Kolayindir Download. This vulnerability affects unknown code of the file down.asp. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2007-0140. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Russian ‘WhisperGate’ Hacks: 5 More Indicted
1 year 6 months ago
Eaten by a GRU: Fake ransomware created by Russian GRU Unit 29155 attacked Ukraine and NATO—a month before the full scale invasion.
The post Russian ‘WhisperGate’ Hacks: 5 More Indicted appeared first on Security Boulevard.
Richi Jennings