Aggregator
CVE-2024-7709 | OcoMon 4.0 URL require_access_recovery.php cross site scripting
1 year 7 months ago
A vulnerability, which was classified as problematic, has been found in OcoMon 4.0. This issue affects some unknown processing of the file /includes/common/require_access_recovery.php of the component URL Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-7709. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DOJ Shuts Down Another North Korean ‘Laptop Farm’
1 year 7 months ago
Federal law enforcement is continuing to target participants in ongoing North Korean schemes to get
DOJ Shuts Down Another North Korean ‘Laptop Farm’
1 year 7 months ago
The DOJ shut down another "laptop farm" link to a North Korean fake IT worker scam that the country uses to illegally bring in money for its nuclear and ballistic weapons program and to steal information from unsuspecting companies in the United States and elsewhere.
The post DOJ Shuts Down Another North Korean ‘Laptop Farm’ appeared first on Security Boulevard.
Jeffrey Burt
CVE-2024-40500 | Martin Kucej i-librarian up to 5.11.0 Import search cross site scripting
1 year 7 months ago
A vulnerability classified as problematic was found in Martin Kucej i-librarian up to 5.11.0. This vulnerability affects the function search of the component Import. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-40500. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-42545 | TOTOLINK A3700R 9.1.2u.5822_B20200513 setWizardCfg ssid buffer overflow
1 year 7 months ago
A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWizardCfg. The manipulation of the argument ssid leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-42545. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-42543 | TOTOLINK A3700R 9.1.2u.5822_B20200513 loginauth http_host buffer overflow
1 year 7 months ago
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function loginauth. The manipulation of the argument http_host leads to buffer overflow.
This vulnerability is handled as CVE-2024-42543. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-41651 | PrestaShop up to 8.1.7 Module Upgrade Privilege Escalation
1 year 7 months ago
A vulnerability was found in PrestaShop up to 8.1.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Module Upgrade. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-41651. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-7700 | Red Hat Satellite 6 Host Init Config Template Install Packages command injection
1 year 7 months ago
A vulnerability was found in Red Hat Satellite 6. It has been classified as critical. Affected is an unknown function of the component Host Init Config Template. The manipulation of the argument Install Packages leads to command injection.
This vulnerability is traded as CVE-2024-7700. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-41475 | GNU Gnuboard 6.0.7 cross-domain policy
1 year 7 months ago
A vulnerability was found in GNU Gnuboard 6.0.7 and classified as critical. This issue affects some unknown processing. The manipulation leads to permissive cross-domain policy with untrusted domains.
The identification of this vulnerability is CVE-2024-41475. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-42474 | Streamlit up to 1.36.x on Windows Static File Sharing path traversal (GHSA-rxff-vr5r-8cj5)
1 year 7 months ago
A vulnerability has been found in Streamlit up to 1.36.x on Windows and classified as critical. This vulnerability affects unknown code of the component Static File Sharing. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-42474. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Ukraine CERT: Mass Phishing Campaign Poses as Nation's Security Service
1 year 7 months ago
More than 100 Ukrainian government devices have been affected by the threat that is being tracked as UAC-0198.
Dark Reading Staff
LEDA 12535: необычная галактика раскрывает секреты космической эволюции
1 year 7 months ago
Обнаружена редкая структура, которая вызывает множество вопросов.
Australian gold producer Evolution Mining hit by ransomware
1 year 7 months ago
error code: 1106
Hackers posing as Ukraine’s Security Service infect 100 govt PCs
1 year 7 months ago
error code: 1106
Hackers posing as Ukraine’s Security Service infect 100 govt PCs
1 year 7 months ago
Attackers impersonating the Security Service of Ukraine (SSU) have used malicious spam emails to target and compromise systems belonging to the country's government agencies. [...]
Sergiu Gatlan
Australian gold producer Evolution Mining hit by ransomware
1 year 7 months ago
Evolution Mining has informed that it has been targeted by a ransomware attack on August 8, 2024, which impacted its IT systems. [...]
Bill Toulas
CLFS Bug Crashes Even Updated Windows 10, 11 Systems
1 year 7 months ago
A quick and easy exploit for crashing Windows computers has no fix yet nor really any way to mitigate its effects.
Nate Nelson, Contributing Writer
Positive Hack Camp: как Россия обучает мир цифровой защите
1 year 7 months ago
Международный проект Positive Technologies запущен при поддержке Минцифры России.
A FreeBSD flaw could allow remote code execution, patch it now!
1 year 7 months ago
FreeBSD Project maintainers addressed a high-severity flaw in OpenSSH that could allow remote code execution with elevated privileges. The maintainers of the FreeBSD Project have released urgent security updates to address a high-severity flaw, tracked as CVE-2024-7589, (CVSS score of 7.4) in OpenSSH. A remote attacker could exploit the vulnerability to execute arbitrary code with elevated […]
Pierluigi Paganini