Aggregator
.NET 一款支持冰蝎的免杀WebShell
1 year 8 months ago
CVE-2014-7024 | Pdlk Hardest Game Collection 1.5.0 X.509 Certificate cryptographic issues (VU#582497)
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in Pdlk Hardest Game Collection 1.5.0. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-7024. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2016-6160 | tcpreplay up to 4.1.1 tcprewrite Frame resource management (ID 251 / Nessus ID 91977)
1 year 8 months ago
A vulnerability, which was classified as problematic, has been found in tcpreplay up to 4.1.1. This issue affects some unknown processing of the component tcprewrite. The manipulation as part of Frame leads to improper resource management.
The identification of this vulnerability is CVE-2016-6160. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Weekly Report: Gitlabにデジタル署名の不適切な検証の脆弱性
1 year 8 months ago
Gitlabには、デジタル署名の不適切な検証の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。
Inaugural World Tour 2024 Survey Findings
1 year 8 months ago
Trend surveyed 750 cybersecurity professionals in 49 countries to learn more about the state of cybersecurity, from job pressures to the need for more advanced tools. Explore what CISOs had to say.
Cybersecurity Compass: Bridging the Communication Gap
1 year 8 months ago
Discover how to use the Cybersecurity Compass to foster effective conversations about cybersecurity strategy between non-technical and technical audiences, focusing on the phases of before, during, and after a breach.
Juan Pablo Castro
CVE-2024-23179 | MediaWiki up to 1.40.1 GlobalBlocking Extension Special:GlobalBlock uselang cross site scripting
1 year 8 months ago
A vulnerability classified as problematic was found in MediaWiki up to 1.40.1. This vulnerability affects unknown code of the file Special:GlobalBlock of the component GlobalBlocking Extension. The manipulation of the argument uselang leads to cross site scripting.
This vulnerability was named CVE-2024-23179. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-6334 | HYPR Workforce Access up to 8.6 on Windows memory corruption
1 year 8 months ago
A vulnerability was found in HYPR Workforce Access up to 8.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2023-6334. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-5097 | HYPR Workforce Access up to 8.6 on Windows path traversal
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in HYPR Workforce Access up to 8.6 on Windows. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2023-5097. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23743 | Notion up to 3.1.0 on macOS RunAsNode/enableNodeClilnspectArguments Privilege Escalation
1 year 8 months ago
A vulnerability was found in Notion up to 3.1.0 on macOS. It has been classified as critical. This affects an unknown part. The manipulation of the argument RunAsNode/enableNodeClilnspectArguments leads to Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-23743. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-6387 | Silabs Gecko SDK prior 4.4.0 Bluetooth LE HCI CPC Sample Application buffer size
1 year 8 months ago
A vulnerability classified as critical has been found in Silabs Gecko SDK. Affected is an unknown function of the component Bluetooth LE HCI CPC Sample Application. The manipulation leads to incorrect calculation of buffer size.
This vulnerability is traded as CVE-2023-6387. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-6874 | Silabs GSDK up to 7.3.x Ember ZNet unusual condition
1 year 8 months ago
A vulnerability was found in Silabs GSDK up to 7.3.x. It has been rated as critical. Affected by this issue is some unknown functionality of the component Ember ZNet. The manipulation leads to improper check for unusual conditions.
This vulnerability is handled as CVE-2023-6874. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-51393 | Silabs Ember ZNet SDK 7.4.0 allocation of resources
1 year 8 months ago
A vulnerability was found in Silabs Ember ZNet SDK 7.4.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2023-51393. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-51395 | Silicon Labs Z-Wave SDK up to 7.17.4/7.18.7/7.19.2 on ARM32 buffer overflow
1 year 8 months ago
A vulnerability classified as critical was found in Silicon Labs Z-Wave SDK up to 7.17.4/7.18.7/7.19.2 on ARM32. This vulnerability affects unknown code. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2023-51395. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
2024-09-23 SNIPBOT RomCom Multi-Stage RAT Samples
1 year 8 months ago
Mila
CVE-2014-7023 | Find Color 1.1.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 8 months ago
A vulnerability classified as critical was found in Find Color 1.1.1. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-7023. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2012-0207 | Linux Kernel net/ipv4/igmp.c igmp_heard_query resource management (EDB-18378 / Nessus ID 802295)
1 year 8 months ago
A vulnerability was found in Linux Kernel and classified as problematic. This issue affects the function igmp_heard_query of the file net/ipv4/igmp.c. The manipulation leads to improper resource management.
The identification of this vulnerability is CVE-2012-0207. The attack can only be done within the local network. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2007-3808 | PHP Arena paFileDB 3.6 includes/search.php categories[] sql injection (EDB-4186 / Nessus ID 25708)
1 year 8 months ago
A vulnerability was found in PHP Arena paFileDB 3.6. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file includes/search.php. The manipulation of the argument categories[] leads to sql injection.
This vulnerability is known as CVE-2007-3808. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
To Be a Cybersecurity Pro, Think Like a Puzzle Solver
1 year 8 months ago
How Curiosity and Gamification Drive Cybersecurity Excellence
Curiosity is one of the most important traits for success in cybersecurity. Professionals in this field regularly face complex problems that require an inquisitive mind, and gamified, hands-on learning is one of the best ways to develop an inquisitive mindset.
Curiosity is one of the most important traits for success in cybersecurity. Professionals in this field regularly face complex problems that require an inquisitive mind, and gamified, hands-on learning is one of the best ways to develop an inquisitive mindset.