Aggregator
CVE-2004-0312 | Linksys WAP55AG 1.0.7 information disclosure (EDB-23721 / XFDB-15257)
2 months 3 weeks ago
A vulnerability was found in Linksys WAP55AG 1.0.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2004-0312. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2016-10034 | Zend Framework up to 2.4.10/2.5.x/2.6.x/2.7.1 zend-mail setFrom command injection (EDB-40979 / Nessus ID 108931)
2 months 3 weeks ago
A vulnerability has been found in Zend Framework up to 2.4.10/2.5.x/2.6.x/2.7.1 and classified as critical. This vulnerability affects the function setFrom of the component zend-mail. The manipulation leads to command injection.
This vulnerability was named CVE-2016-10034. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-1648 | Open-Xchange Server 6.20.7/6.22.0/6.22.1 Gopher input validation (EDB-24791 / ID 803182)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Open-Xchange Server 6.20.7/6.22.0/6.22.1. Affected is an unknown function of the component Gopher. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2013-1648. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
白泽ers Happy 1024 Day!程序员专属节日,代码改变世界!
2 months 3 weeks ago
白泽ers Happy 1024 Day!
CVE-2002-0686 | Iplanet Web Server 4.1 NS-rel-doc-name memory corruption (VU#612843 / XFDB-9506)
2 months 3 weeks ago
A vulnerability was found in Iplanet Web Server 4.1. It has been classified as critical. This affects an unknown part. The manipulation of the argument NS-rel-doc-name leads to memory corruption.
This vulnerability is uniquely identified as CVE-2002-0686. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Unforeseen Risks to Medical Devices in Ransomware Attacks
2 months 3 weeks ago
While ransomware attacks against medical devices don't happen often, disruptive cyber incidents that affect the availability of the IT systems that medical devices rely on are a big concern that needs the industry's critical attention, said Jessica Wilkerson of the FDA.
Breach Roundup: CISA Proposes Security for Bulk Data Sales
2 months 3 weeks ago
Also: Payment Card Theft Trends, Internet Archive Update
This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
Hackers Probing Newly Disclosed Fortinet Zero-Day
2 months 3 weeks ago
Mandiant Says High-Severity Flaw Could Give Attackers Remote Unauthenticated Access
Researchers at Mandiant say a new threat cluster, first observed June 27, has been exploiting a Fortinet zero-day that the network edge device manufacturer publicly disclosed Wednesday. Researchers said they can't assess the threat actor's motivation or location.
Researchers at Mandiant say a new threat cluster, first observed June 27, has been exploiting a Fortinet zero-day that the network edge device manufacturer publicly disclosed Wednesday. Researchers said they can't assess the threat actor's motivation or location.
Socure to Fortify Identity Services With $136M Effectiv Buy
2 months 3 weeks ago
Effectiv's 30-Person Team to Streamline Identity Services, Help Socure Grow Revenue
Socure has acquired Effectiv, integrating its engineering team of 30 to strengthen identity verification capabilities. The $136 million deal aims to speed up customer onboarding, enhance transaction monitoring, and deliver cross-platform solutions, with the product integration expected in 45 days.
Socure has acquired Effectiv, integrating its engineering team of 30 to strengthen identity verification capabilities. The $136 million deal aims to speed up customer onboarding, enhance transaction monitoring, and deliver cross-platform solutions, with the product integration expected in 45 days.
LinkedIn Fined 310 Million Euros for Privacy Violations
2 months 3 weeks ago
Irish Data Protection Commission Cites Social Platform for GDPR Violations
The Irish Data Protection Commission imposed a 310 million euro fine on LinkedIn for violating a European privacy law stemming from the company's use of customer data. It ordered the social media platform to bring its data processing under compliance.
The Irish Data Protection Commission imposed a 310 million euro fine on LinkedIn for violating a European privacy law stemming from the company's use of customer data. It ordered the social media platform to bring its data processing under compliance.
Apple creates Private Cloud Compute VM to let researchers find bugs
2 months 3 weeks ago
Apple created a Virtual Research Environment to allow public access to testing the security of its Private Cloud Compute system, and released the source code for some "key components" to help researchers analyze the privacy and safety features on the architecture. [...]
Ionut Ilascu
CVE-2024-50034 | Linux Kernel up to 6.11.3 icsk_syn_mss null pointer dereference (44dc50df15f5/6fd27ea183c2)
2 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.11.3. It has been classified as critical. Affected is the function icsk_syn_mss. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-50034. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50033 | Linux Kernel up to 5.10.226/5.15.167/6.1.112/6.6.56/6.11.3 slhc_remember uninitialized resource
2 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 5.10.226/5.15.167/6.1.112/6.6.56/6.11.3. It has been declared as problematic. This vulnerability affects the function slhc_remember. The manipulation leads to uninitialized resource.
This vulnerability was named CVE-2024-50033. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49013 | Linux Kernel up to 5.4.225/5.10.157/5.15.81/6.0.11 sctp_stream_outq_migrate memory leak
2 months 3 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 5.4.225/5.10.157/5.15.81/6.0.11. This vulnerability affects the function sctp_stream_outq_migrate. The manipulation leads to memory leak.
This vulnerability was named CVE-2022-49013. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49019 | Linux Kernel up to 5.4.225/5.10.157/5.15.81/6.0.11 nixge_hw_dma_bd_release null pointer dereference
2 months 3 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 5.4.225/5.10.157/5.15.81/6.0.11. Affected is the function nixge_hw_dma_bd_release. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2022-49019. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49021 | Linux Kernel up to 6.0.11 phy probe null pointer dereference
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.0.11. Affected by this issue is the function probe of the component phy. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2022-49021. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49022 | Linux Kernel up to 5.10.157/5.15.81/6.0.11 net/mac80211/airtime.c ieee80211_get_rate_duration array index
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.157/5.15.81/6.0.11. This affects the function ieee80211_get_rate_duration of the file net/mac80211/airtime.c. The manipulation leads to improper validation of array index.
This vulnerability is uniquely identified as CVE-2022-49022. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50035 | Linux Kernel up to 5.10.226/5.15.167/6.1.112/6.6.56/6.11.3 ppp_async.c ppp_async_encode uninitialized resource
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.10.226/5.15.167/6.1.112/6.6.56/6.11.3. This affects the function ppp_async_encode of the file drivers/net/ppp/ppp_async.c. The manipulation leads to uninitialized resource.
This vulnerability is uniquely identified as CVE-2024-50035. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50041 | Linux Kernel up to 5.15.167/6.1.112/6.6.56/6.11.3 i40e_del_mac_filter memory leak
2 months 3 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 5.15.167/6.1.112/6.6.56/6.11.3. This affects the function i40e_del_mac_filter. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2024-50041. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com