Aggregator
.NET内网实战:通过调用系统的API接口模拟实现PowerShell
6 days 11 hours ago
CVE-2015-0235 | Oracle Communications EAGLE Application Processor 16 memory corruption (EDB-35951 / Nessus ID 81024)
6 days 11 hours ago
A vulnerability, which was classified as very critical, was found in Oracle Communications EAGLE Application Processor 16. Affected is an unknown function. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2015-0235. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Interlock
6 days 11 hours ago
cohenido
Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE
6 days 11 hours ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Fortinet releases patches for publicly undisclosed critical FortiManager vulnerability In the last couple of days, Fortinet has released critical security updates for FortiManager, to fix a critical vulnerability that is reportedly being exploited by Chinese threat actors. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812) Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter … More →
The post Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE appeared first on Help Net Security.
Help Net Security
CVE-2024-10412 | Poco-z Guns-Medical 1.0 File Upload /mgr/upload picture cross site scripting (文件上传未过滤 #15)
6 days 11 hours ago
A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /mgr/upload of the component File Upload. The manipulation of the argument picture leads to cross site scripting.
This vulnerability is known as CVE-2024-10412. The attack can be launched remotely. There is no exploit available.
vuldb.com
Handala
6 days 11 hours ago
cohenido
Cyber Attack on Israel Volleyball Association Claimed by DarkRaaS
6 days 11 hours ago
cohenido
CVE-2008-2684 | Black Ice Barcode SDK 5.01 ActiveX Control bidib.ocx code injection (EDB-5750 / XFDB-42896)
6 days 11 hours ago
A vulnerability classified as very critical has been found in Black Ice Barcode SDK 5.01. Affected is an unknown function of the file bidib.ocx of the component ActiveX Control. The manipulation leads to code injection.
This vulnerability is traded as CVE-2008-2684. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2691 | JiRo FAQ Manager eXperience 1.0 read.asp fID sql injection (EDB-5753 / XFDB-42919)
6 days 11 hours ago
A vulnerability was found in JiRo FAQ Manager eXperience 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file read.asp. The manipulation of the argument fID leads to sql injection.
This vulnerability is handled as CVE-2008-2691. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2694 | phpInv 0.8.0 search.php keyword cross site scripting (EDB-5754 / XFDB-42928)
6 days 11 hours ago
A vulnerability, which was classified as problematic, has been found in phpInv 0.8.0. This issue affects some unknown processing of the file search.php. The manipulation of the argument keyword leads to cross site scripting.
The identification of this vulnerability is CVE-2008-2694. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2701 | Com Gameq up to 4.0 on Joomla index.php category_id sql injection (EDB-5752 / XFDB-42929)
6 days 11 hours ago
A vulnerability classified as critical has been found in Com Gameq up to 4.0 on Joomla. Affected is an unknown function of the file index.php. The manipulation of the argument category_id leads to sql injection.
This vulnerability is traded as CVE-2008-2701. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2119 | Digium Asterisk up to 1.2.29 SIP input validation (EDB-5749 / Nessus ID 38677)
6 days 11 hours ago
A vulnerability was found in Digium Asterisk up to 1.2.29. It has been classified as problematic. This affects an unknown part of the component SIP Handler. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2008-2119. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-2683 | Black Ice Barcode SDK 5.01 ActiveX Control bidib.ocx DownloadImageFileURL second input validation (EDB-17415 / XFDB-42891)
6 days 11 hours ago
A vulnerability was found in Black Ice Barcode SDK 5.01. It has been rated as very critical. This issue affects the function DownloadImageFileURL of the file bidib.ocx of the component ActiveX Control. The manipulation of the argument second leads to improper input validation.
The identification of this vulnerability is CVE-2008-2683. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6068 | Web Design Hero JoomlaDate 1.2 index.php user sql injection (EDB-5748 / XFDB-42873)
6 days 11 hours ago
A vulnerability classified as critical was found in Web Design Hero JoomlaDate 1.2. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument user leads to sql injection.
This vulnerability is known as CVE-2008-6068. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
雷军晒小米15发布会首次彩排合影;全华班 BLG 晋级S14决赛;阿里同意支付4.335亿美元和解美股集体诉讼案 | 极客早知道
6 days 11 hours ago
消息称谷歌将推出「Project Jarvis」:可实现网页任务自动化;上汽荣威 D7 DMH 世界冠军版轿车下月初上市;腾讯研发全球首个大熊猫模型
CVE-2010-4250 | Linux Kernel 2.6.36.1/2.6.36.2/2.6.36.3/2.6.36.4 inotify_init1 resource management (RHSA-2011:0498 / EDB-35013)
6 days 12 hours ago
A vulnerability classified as problematic was found in Linux Kernel 2.6.36.1/2.6.36.2/2.6.36.3/2.6.36.4. Affected by this vulnerability is the function inotify_init1. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2010-4250. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
RansomHub
6 days 12 hours ago
cohenido
Технологии-2025: Gartner предсказывает технореволюцию
6 days 12 hours ago
От квантовой криптографии до невидимого интеллекта в рабочей среде.
CVE-2017-2435 | Apple iOS up to 10.2 CoreText memory corruption (HT207617 / EDB-40961)
6 days 12 hours ago
A vulnerability has been found in Apple iOS up to 10.2 and classified as critical. This vulnerability affects unknown code of the component CoreText. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2435. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com