Aggregator
资料下载 | 网络数据安全管理条例、国家数据标准体系建设指南、山东数据要素市场化配置改革、广东省数据条例
1 year 8 months ago
·政策
《网络数据安全管理条例》
《国家数据标准体系建设指南》
山东省《关于加快推进数据要素市场化配置改革的实施意见》
《广东省数据条例(草案征求意见稿)》
·标准
《网络安全技术 网络型防火墙互联互通接口内容和格式》(征求意见稿)
·报告
《数据要素与先进存储融合发展研究报告》
API安全拉响警报 有效防控成为当务之急
1 year 8 months ago
传统API网关或WAF防护难以应对,亟需专注于API的安全解决方案。
CVE-2016-1382 | Cisco Web Security Appliance up to 8.8 HTTP Length Request input validation (cisco-sa-20160518-wsa3 / Nessus ID 91338)
1 year 8 months ago
A vulnerability was found in Cisco Web Security Appliance up to 8.8 and classified as critical. Affected by this issue is some unknown functionality of the component HTTP Length Request Handler. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2016-1382. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DataCon2024漏洞分析赛道 | 快来“挖洞”了,46万赏金等你拿!
1 year 8 months ago
@DataCon2024漏洞分析赛道参赛人
CVE-2005-4071 | CFMagic Magic Forum Personal up to 2.5 view_forum.cfm ForumID sql injection (EDB-26764 / XFDB-23514)
1 year 8 months ago
A vulnerability has been found in CFMagic Magic Forum Personal up to 2.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file view_forum.cfm. The manipulation of the argument ForumID leads to sql injection.
This vulnerability is known as CVE-2005-4071. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
安全热点周报:超过 87,000 台 FortiOS 设备易受远程代码执行攻击
1 year 8 months ago
CVE-2023-5363 | OpenSSL up to 3.0.11/3.1.3 Length keylen/ivlen buffer over-read
1 year 8 months ago
A vulnerability was found in OpenSSL up to 3.0.11/3.1.3 and classified as critical. This issue affects the function EVP_EncryptInit_ex2/EVP_DecryptInit_ex2/EVP_CipherInit_ex2 of the component Length Handler. The manipulation of the argument keylen/ivlen leads to buffer over-read.
The identification of this vulnerability is CVE-2023-5363. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-5363 | Oracle MySQL Connectors 8.2.0 and prior Connector/C++ information disclosure
1 year 8 months ago
A vulnerability classified as critical was found in Oracle MySQL Connectors 8.2.0 and prior. This vulnerability affects unknown code of the component Connector/C++. The manipulation leads to information disclosure.
This vulnerability was named CVE-2023-5363. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-5363 | Oracle MySQL Connectors 8.0.35 and prior/8.2.0 and prior Connector/ODBC information disclosure
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in Oracle MySQL Connectors 8.0.35 and prior/8.2.0 and prior. This issue affects some unknown processing of the component Connector/ODBC. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2023-5363. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-5363 | Oracle MySQL Enterprise Monitor 8.0.36 and prior information disclosure
1 year 8 months ago
A vulnerability has been found in Oracle MySQL Enterprise Monitor 8.0.36 and prior and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-5363. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-5363 | Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior Packaging information disclosure
1 year 8 months ago
A vulnerability was found in Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior and classified as critical. Affected by this issue is some unknown functionality of the component Packaging. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2023-5363. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-5363 | Oracle MySQL Workbench 8.0.34 and prior information disclosure
1 year 8 months ago
A vulnerability was found in Oracle MySQL Workbench 8.0.34 and prior. It has been classified as critical. This affects an unknown part of the component MySQL Workbench. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2023-5363. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Daniel Stori’s Turnoff.US: ‘My Sweet ML Model’
1 year 8 months ago
via the inimitable Daniel Stori at Turnoff.US!
The post Daniel Stori’s Turnoff.US: ‘My Sweet ML Model’ appeared first on Security Boulevard.
Marc Handelman
Nation-state actor exploited three Ivanti CSA zero-days
1 year 8 months ago
An alleged nation-state actor exploited three zero-day vulnerabilities in Ivanti Cloud Service Appliance (CSA) in recent attacks. Fortinet FortiGuard Labs researchers warn that a suspected nation-state actor has been exploiting three Ivanti Cloud Service Appliance (CSA) zero-day issues to carry out malicious activities. The three vulnerabilities exploited by the threat actor are: “an advanced adversary […]
Pierluigi Paganini
CVE-2008-0480 | Web Wiz Forums 9.07 rte_file_browser.asp sub path traversal (EDB-4970 / XFDB-39856)
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in Web Wiz Forums 9.07. Affected is an unknown function of the file rte_file_browser.asp. The manipulation of the argument sub leads to path traversal.
This vulnerability is traded as CVE-2008-0480. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2008-0443 | Lycos FileUploader.dll 2.0.2 ActiveX Control fileuploader.dll memory corruption (EDB-4967 / XFDB-39849)
1 year 8 months ago
A vulnerability was found in Lycos FileUploader.dll 2.0.2. It has been rated as very critical. This issue affects some unknown processing in the library fileuploader.dll of the component ActiveX Control. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2008-0443. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0446 | Julian Pawlowski LulieBlog 1.02 voircom.php id sql injection (EDB-4969 / XFDB-39854)
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in Julian Pawlowski LulieBlog 1.02. Affected by this issue is some unknown functionality of the file voircom.php. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2008-0446. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0447 | Foojan PHP Weblog 1.0 index.php story sql injection (EDB-4968 / XFDB-39855)
1 year 8 months ago
A vulnerability, which was classified as critical, was found in Foojan PHP Weblog 1.0. This affects an unknown part of the file index.php. The manipulation of the argument story leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-0447. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0466 | Webwiz Web Wiz Rich Text Editor 4.0 rte_file_browser.asp improper authentication (EDB-4970 / BID-27419)
1 year 8 months ago
A vulnerability classified as problematic was found in Webwiz Web Wiz Rich Text Editor 4.0. This vulnerability affects unknown code of the file rte_file_browser.asp of the component Rich Text Editor. The manipulation leads to improper authentication.
This vulnerability was named CVE-2008-0466. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com