Aggregator
«Он знает, когда ты спишь и как ты пишешь». ChatGPT начнет сам определять ваш возраст
2 months 2 weeks ago
OpenAI запустила систему автоматического определения возраста пользователей.
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
2 months 2 weeks ago
The recently discovered sophisticated Linux malware framework known as VoidLink is assessed to have been developed by a single person with assistance from an artificial intelligence (AI) model.
That's according to new findings from Check Point Research, which identified operational security blunders by malware's author that provided clues to its developmental origins. The latest insight makes
The Hacker News
CVE-2023-38931 | Tenda AC5/AC6/AC7/AC8/AC10/F1203/FH1203 Parameter setaccount list stack-based overflow (EUVD-2023-42691)
2 months 2 weeks ago
A vulnerability was found in Tenda AC5, AC6, AC7, AC8, AC10, F1203 and FH1203. It has been classified as critical. Affected by this issue is the function setaccount of the component Parameter Handler. Performing a manipulation of the argument list results in stack-based buffer overflow.
This vulnerability is known as CVE-2023-38931. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2023-38933 | Tenda AC6/AC7/AC9/F1203/FH1205 formSetClientState deviceId stack-based overflow (EUVD-2023-42693)
2 months 2 weeks ago
A vulnerability was found in Tenda AC6, AC7, AC9, F1203 and FH1205. It has been declared as critical. This affects the function formSetClientState. Executing a manipulation of the argument deviceId can lead to stack-based buffer overflow.
This vulnerability is handled as CVE-2023-38933. The attack can only be done within the local network. There is not any exploit available.
vuldb.com
CVE-2023-38932 | Tenda F1202/FH1202/PA202/PW201A SafeEmailFilter page stack-based overflow (EUVD-2023-42692)
2 months 2 weeks ago
A vulnerability identified as critical has been detected in Tenda F1202, FH1202, PA202 and PW201A. Affected by this vulnerability is the function SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2023-38932. The attack can only be initiated within the local network. No exploit exists.
vuldb.com
CVE-2023-38930 | Tenda AC5/AC7/AC9/F1203/FH1205 addWifiMacFilter deviceId stack-based overflow (EUVD-2023-42690)
2 months 2 weeks ago
A vulnerability was found in Tenda AC5, AC7, AC9, F1203 and FH1205 and classified as critical. Affected by this vulnerability is the function addWifiMacFilter. Such manipulation of the argument deviceId leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2023-38930. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-8194 | CPython up to 3.13.x tarfile infinite loop (Issue 130577 / Nessus ID 243944)
2 months 2 weeks ago
A vulnerability was found in CPython up to 3.13.x. It has been declared as problematic. Impacted is an unknown function of the component tarfile Module. Such manipulation leads to infinite loop.
This vulnerability is referenced as CVE-2025-8194. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-55163 | Netty prior 4.1.124.Final/4.2.4.Final HTTP/2 allocation of resources (GHSA-prj3-ccx8-p6x4 / EUVD-2025-28583)
2 months 2 weeks ago
A vulnerability marked as problematic has been reported in Netty. This issue affects some unknown processing of the component HTTP2 Handler. This manipulation causes allocation of resources.
The identification of this vulnerability is CVE-2025-55163. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-5115 | Eclipse Jetty resource consumption (EUVD-2025-25397 / Nessus ID 258063)
2 months 2 weeks ago
A vulnerability was found in Eclipse Jetty up to 9.4.57/10.0.25/11.0.25/12.0.21/12.1.0.alpha2. It has been declared as problematic. This affects an unknown part. Executing a manipulation can lead to resource consumption.
This vulnerability is tracked as CVE-2025-5115. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-8671 | IETF HTTP Working Group Fastly H20/HTTP/2 Stream Reset MadeYouReset resource consumption (VU#767506 / EUVD-2025-24560)
2 months 2 weeks ago
A vulnerability identified as critical has been detected in IETF HTTP Working Group Fastly H20 and HTTP2. The impacted element is an unknown function of the component Stream Reset Handler. This manipulation causes resource consumption.
The identification of this vulnerability is CVE-2025-8671. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-55166 | darylldoyle svg-sanitizer up to 0.21.x Attribute Name cleanXlinkHrefs cross site scripting (WID-SEC-2025-1834)
2 months 2 weeks ago
A vulnerability labeled as problematic has been found in darylldoyle svg-sanitizer up to 0.21.x. This affects the function cleanXlinkHrefs of the component Attribute Name Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-55166. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-38615 | Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0 ntfs3 make_bad_inode denial of service (Nessus ID 260128 / WID-SEC-2025-1869)
2 months 2 weeks ago
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0. This affects the function make_bad_inode of the component ntfs3. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2025-38615. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-48989 | Apache Tomcat up to 8.5.100/9.0.107/10.1.43/11.0.9 HTTP/2 denial of service (EUVD-2025-24559 / Nessus ID 249345)
2 months 2 weeks ago
A vulnerability categorized as problematic has been discovered in Apache Tomcat up to 8.5.100/9.0.107/10.1.43/11.0.9. The affected element is an unknown function of the component HTTP2 Handler. The manipulation results in denial of service. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-48989. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-38614 | Linux Kernel up to 6.16.0 eventpoll ep_loop_check_proc recursion (Nessus ID 260130 / WID-SEC-2025-1869)
2 months 2 weeks ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.16.0. This issue affects the function ep_loop_check_proc of the component eventpoll. The manipulation results in uncontrolled recursion.
This vulnerability is known as CVE-2025-38614. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
vuldb.com
Cursor配置有大坑,已被黑客组织“借刀杀人”
2 months 2 weeks ago
Cursor配置有大坑,已被黑客组织“借刀杀人”
CVE-2026-24016 | Fsas ServerView Agents for Windows on Windows uncontrolled search path
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Fsas ServerView Agents for Windows on Windows. This vulnerability affects unknown code. Performing a manipulation results in uncontrolled search path.
This vulnerability is reported as CVE-2026-24016. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2025-65586 | libheif up to 1.19.7 HEIF Image out-of-bounds
2 months 2 weeks ago
A vulnerability classified as problematic was found in libheif up to 1.19.7. This affects an unknown part of the component HEIF Image Handler. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2025-65586. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38613 | Linux Kernel up to 6.16.0 board_info_ioctl initialization (Nessus ID 260179 / WID-SEC-2025-1869)
2 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.16.0 and classified as problematic. This issue affects the function board_info_ioctl. Executing a manipulation can lead to improper initialization.
This vulnerability is tracked as CVE-2025-38613. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-38611 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 IOCTL Call vmci_datagram_dispatch initialization (EUVD-2025-26089 / WID-SEC-2025-1869)
2 months 2 weeks ago
This issue appears to be a false-positive. Please verify the sources mentioned and consider not using this entry at all.
vuldb.com