Aggregator
CVE-2007-2204 | GPL PHP Board unstable-2001.11.14-1 mysqli db.mysql.inc.php theme file inclusion (EDB-3786 / XFDB-33839)
2 months 1 week ago
A vulnerability has been found in GPL PHP Board unstable-2001.11.14-1 and classified as critical. This vulnerability affects unknown code of the file db.mysql.inc.php of the component mysqli. The manipulation of the argument theme leads to file inclusion.
This vulnerability was named CVE-2007-2204. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-5979 | TVBengali Open Directory 1.4 X.509 Certificate cryptographic issues (VU#582497)
2 months 1 week ago
A vulnerability classified as critical was found in TVBengali Open Directory 1.4. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-5979. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2014-5978 | Ipposan memetan 1.1.0 X.509 Certificate cryptographic issues (VU#582497)
2 months 1 week ago
A vulnerability classified as critical has been found in Ipposan memetan 1.1.0. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-5978. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2002-0813 | Cisco IOS 11.1/11.2/11.3 TFTP Server filename memory corruption (EDB-21655 / Nessus ID 18264)
2 months 1 week ago
A vulnerability was found in Cisco IOS 11.1/11.2/11.3. It has been classified as very critical. This affects an unknown part of the component TFTP Server. The manipulation of the argument filename leads to memory corruption.
This vulnerability is uniquely identified as CVE-2002-0813. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8583 | SourceCodester Online Bank Management System 1.0 Feedback /mfeedback.php cross site scripting
2 months 1 week ago
A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects an unknown part of the file /mfeedback.php of the component Feedback Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-8583. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8582 | SourceCodester Food Ordering Management System 1.0 /index.php description cross site scripting
2 months 1 week ago
A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument description leads to cross site scripting.
This vulnerability is handled as CVE-2024-8582. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-42342 | Loway QueueMetrics request smuggling
2 months 1 week ago
A vulnerability has been found in Loway QueueMetrics and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to http request smuggling.
This vulnerability is known as CVE-2024-42342. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42341 | Loway QueueMetrics redirect
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in Loway QueueMetrics. Affected is an unknown function. The manipulation leads to open redirect.
This vulnerability is traded as CVE-2024-42341. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42343 | Loway QueueMetrics observable response discrepancy
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Loway QueueMetrics. This issue affects some unknown processing. The manipulation leads to observable response discrepancy.
The identification of this vulnerability is CVE-2024-42343. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #404611: SourceCodester Online Bank Management System 1.0 Storage-optimized Cross-site scripting vulnerability [Accepted]
2 months 1 week ago
Submit #404611 / VDB-276819
Niu-zida
CVE-2014-5977 | Mobile Face 0.74.13432.91159 X.509 Certificate cryptographic issues (VU#582497)
2 months 1 week ago
A vulnerability was found in Mobile Face 0.74.13432.91159. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-5977. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
Submit #404604: SourceCodester Food Ordering Management System 1.0 Cross-Site Scripting [Accepted]
2 months 1 week ago
Submit #404604 / VDB-276818
Niu-zida
CVE-2017-13035 | tcpdump up to 4.9.1 ISO IS-IS Parser print-isoclns.c isis_print_id memory corruption (Nessus ID 103257 / ID 370625)
2 months 1 week ago
A vulnerability classified as critical has been found in tcpdump up to 4.9.1. Affected is the function isis_print_id of the file print-isoclns.c of the component ISO IS-IS Parser. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2017-13035. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-5976 | alibaba 4.1.0.0 X.509 Certificate cryptographic issues (VU#582497)
2 months 1 week ago
A vulnerability was found in alibaba 4.1.0.0. It has been declared as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-5976. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
USENIX Security ’23 – Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels
2 months 1 week ago
Authors/Presenters:Andreas Kogler, Jonas Juffinger, Lukas Giner, Lukas Gerlach, Martin Schwarzl, Michael Schwarz, Daniel Gruss, Stefan Mangard
Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the organizations YouTube channel.
The post USENIX Security ’23 – Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels appeared first on Security Boulevard.
Marc Handelman
CVE-2017-13034 | Apple macOS up to 10.13.1 tcpdump memory corruption (HT208221 / Nessus ID 100472)
2 months 1 week ago
A vulnerability classified as very critical was found in Apple macOS up to 10.13.1. Affected by this vulnerability is an unknown functionality of the component tcpdump. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2017-13034. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-5975 | Grabapp eponyms 3.2 X.509 Certificate cryptographic issues (VU#582497)
2 months 1 week ago
A vulnerability was found in Grabapp eponyms 3.2. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-5975. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2008-5896 | CodeAvalanche RateMySite access control (EDB-7472 / XFDB-47350)
2 months 1 week ago
A vulnerability was found in CodeAvalanche RateMySite. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2008-5896. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-4231 | Camtron CMNC-200 1.102a-008 Administration Interface path traversal (EDB-15505 / XFDB-63263)
2 months 1 week ago
A vulnerability was found in Camtron CMNC-200 1.102a-008. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Administration Interface. The manipulation leads to path traversal.
This vulnerability is known as CVE-2010-4231. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com