Aggregator
Геолокацию объектов НАТО и Европарламента теперь продают так же легко, как рекламу
3 months 1 week ago
Европейский "цифровой суверенитет" утек в "пробную выборку" на 278 миллионов записей.
Microsoft: October Windows updates trigger BitLocker recovery
3 months 1 week ago
Microsoft has warned that some systems may boot into BitLocker recovery after installing the October 2025 Windows security updates. [...]
Sergiu Gatlan
微软测试用 Copilot 取代桌面搜索框
3 months 1 week ago
微软正将其 AI 助手 Copilot 集成到其每一个产品之中,而 Windows 操作系统则在更深入的整合 Copilot。微软在最新 Windows Insider Dev 和 Beta 版本中测试了用 Copilot 取代传统的桌面搜索框。Copilot 搜索框并没有默认启用,默认的搜索框显示了文字“搜索”,在用 Copilot 取代之后,搜索框会显示文字“问 Copilot 任何事”,用户可以输入 Copilot 提示词或搜索关键词。 目前的测试显示它并没有传统搜索功能强。
Centraleyes AI Framework (CAIF)
3 months 1 week ago
What is the CAIF? The Centraleyes AI Framework (CAIF) is a comprehensive compliance and governance tool designed to help organizations meet the diverse and rapidly evolving regulatory requirements surrounding artificial intelligence. It consolidates questions and controls from multiple AI laws and regulatory regimes across the globe – including the EU AI Act (Minimal and Limited […]
The post Centraleyes AI Framework (CAIF) appeared first on Centraleyes.
The post Centraleyes AI Framework (CAIF) appeared first on Security Boulevard.
Naomi Scarr
CVE-2020-10735 | Python 000/100 Non-binary Base float/decimal/int.from_bytes/int denial of service (Issue 95778 / Nessus ID 211850)
3 months 1 week ago
A vulnerability has been found in Python 000/100 and classified as problematic. This affects the function float/decimal/int.from_bytes/int of the component Non-binary Base Handler. This manipulation causes denial of service.
This vulnerability appears as CVE-2020-10735. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2022-37703 | Amanda 3.5.1 calcsize opendir privileges management
3 months 1 week ago
A vulnerability classified as critical has been found in Amanda 3.5.1. This affects the function opendir of the component calcsize. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2022-37703. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-40468 | Tinyproxy HTTP Request process_request information disclosure (Issue 457 / Nessus ID 213503)
3 months 1 week ago
A vulnerability marked as problematic has been reported in Tinyproxy. The impacted element is the function process_request of the component HTTP Request Handler. Performing manipulation results in information disclosure.
This vulnerability was named CVE-2022-40468. The attack needs to be approached within the local network. There is no available exploit.
vuldb.com
CVE-2022-39956 | OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.1/3.3.2 HTTP Multipart Request Content-Type/Content-Transfer-Encoding authorization (FEDORA-2022-85a85c84b3)
3 months 1 week ago
A vulnerability classified as critical has been found in OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.1/3.3.2. Affected is an unknown function of the component HTTP Multipart Request Handler. This manipulation of the argument Content-Type/Content-Transfer-Encoding causes incorrect authorization.
This vulnerability is handled as CVE-2022-39956. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-39958 | OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.0/3.2.1/3.3.2 Response Body Range authorization (FEDORA-2022-85a85c84b3)
3 months 1 week ago
A vulnerability classified as critical was found in OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.0/3.2.1/3.3.2. Affected by this vulnerability is an unknown functionality of the component Response Body Handler. Such manipulation of the argument Range leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2022-39958. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2020-10735 | Oracle Database Server 21c denial of service (Nessus ID 211850)
3 months 1 week ago
A vulnerability classified as critical has been found in Oracle Database Server 21c. Affected is an unknown function of the component Oracle Database. The manipulation leads to denial of service.
This vulnerability is referenced as CVE-2020-10735. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2020-10735 | Oracle Communications Cloud Native Core Binding Support Function Install/Upgrade denial of service (Nessus ID 211850)
3 months 1 week ago
A vulnerability labeled as critical has been found in Oracle Communications Cloud Native Core Binding Support Function 22.2.1. This vulnerability affects unknown code of the component Install/Upgrade. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2020-10735. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2020-10735 | Oracle MySQL Shell up to 8.0.31 Core Client denial of service (Nessus ID 211850)
3 months 1 week ago
A vulnerability marked as critical has been reported in Oracle MySQL Shell up to 8.0.31. The impacted element is an unknown function of the component Core Client. Performing manipulation results in denial of service.
This vulnerability is known as CVE-2020-10735. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2020-10735 | Oracle Communications Cloud Native Core Network Function Cloud Native Environment Configuration denial of service (Nessus ID 211850)
3 months 1 week ago
A vulnerability labeled as critical has been found in Oracle Communications Cloud Native Core Network Function Cloud Native Environment 23.1.0. This affects an unknown part of the component Configuration. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2020-10735. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2022-38648 | Apache XML Graphics Batik 1.14 server-side request forgery (Nessus ID 242417)
3 months 1 week ago
A vulnerability marked as critical has been reported in Apache XML Graphics Batik 1.14. This vulnerability affects unknown code. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2022-38648. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2022-40146 | Apache XML Graphics Batik 1.14 JAR URL server-side request forgery (Nessus ID 242417)
3 months 1 week ago
A vulnerability classified as critical has been found in Apache XML Graphics Batik 1.14. Impacted is an unknown function of the component JAR URL Handler. Performing manipulation results in server-side request forgery.
This vulnerability was named CVE-2022-40146. The attack needs to be approached within the local network. There is no available exploit.
vuldb.com
CVE-2022-40146 | Oracle Communications MetaSolv Solution 6.3.1 Utilities information disclosure (Nessus ID 242417)
3 months 1 week ago
A vulnerability was found in Oracle Communications MetaSolv Solution 6.3.1. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Utilities. Performing manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2022-40146. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-39955 | OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.0/3.2.1 HTTP Header Content-Type authorization (FEDORA-2022-85a85c84b3)
3 months 1 week ago
A vulnerability described as critical has been identified in OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.0/3.2.1. This impacts an unknown function of the component HTTP Header Handler. The manipulation of the argument Content-Type results in incorrect authorization.
This vulnerability is known as CVE-2022-39955. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-39957 | OWASP ModSecurity Core Rule Set up to 3.3.2 Response Body Accept protection mechanism (FEDORA-2022-85a85c84b3)
3 months 1 week ago
A vulnerability, which was classified as critical, has been found in OWASP ModSecurity Core Rule Set up to 3.3.2. Affected by this issue is some unknown functionality of the component Response Body Handler. Performing manipulation of the argument Accept results in protection mechanism failure.
This vulnerability was named CVE-2022-39957. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2020-10735 | Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59/8.60 Porting denial of service (Nessus ID 211850)
3 months 1 week ago
A vulnerability has been found in Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59/8.60 and classified as critical. This affects an unknown function of the component Porting. This manipulation causes denial of service.
The identification of this vulnerability is CVE-2020-10735. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com