Aggregator
司法部、国家网信办负责人就《网络数据安全管理条例》答记者问
3 months ago
《网络数据安全管理条例 》
3 months ago
CVE-2024-43523 | Microsoft Windows up to Server 2022 23H2 Mobile Broadband Driver heap-based overflow
3 months ago
A vulnerability was found in Microsoft Windows up to Server 2022 23H2 and classified as critical. Affected by this issue is some unknown functionality of the component Mobile Broadband Driver. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-43523. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
SAP security advisory – October 2024 monthly rollup (AV24-569)
3 months ago
Canadian Centre for Cyber Security
CVE-2024-43522 | Microsoft Windows 11 22H2/11 23H2 Local Security Authority heap-based overflow
3 months ago
A vulnerability has been found in Microsoft Windows 11 22H2/11 23H2 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Local Security Authority. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-43522. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43521 | Microsoft Windows Server 2012 up to Server 2022 Hyper-V incorrect check of function return value
3 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows Server 2012 up to Server 2022. Affected is an unknown function of the component Hyper-V. The manipulation leads to incorrect check of function return value.
This vulnerability is traded as CVE-2024-43521. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Ivanti fixes three CSA zero-days exploited in the wild (CVE-2024-9379, CVE-2024-9380, CVE-2024-9381)
3 months ago
Ivanti has patched three additional Cloud Service Appliance (CSA) zero-day flaws, which have been exploited by attackers in conjuction with a zero-day bug the company accidentally fixed in September. The fixed zero-days “We are aware of a limited number of customers running CSA 4.6 patch 518 and prior who have been exploited when CVE-2024-9379, CVE-2024-9380 or CVE-2024-9381 are chained with CVE-2024-8963,” the company announced on Tuesday. CVE-2024-8963 is a path traversal vulnerability that allows a … More →
The post Ivanti fixes three CSA zero-days exploited in the wild (CVE-2024-9379, CVE-2024-9380, CVE-2024-9381) appeared first on Help Net Security.
Zeljka Zorz
CVE-2024-43528 | Microsoft Windows up to Server 2022 23H2 Secure Kernel Mode heap-based overflow
3 months ago
A vulnerability classified as critical was found in Microsoft Windows up to Server 2022 23H2. Affected by this vulnerability is an unknown functionality of the component Secure Kernel Mode. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-43528. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43520 | Microsoft Windows up to Server 2022 23H2 Kernel null pointer dereference
3 months ago
A vulnerability, which was classified as problematic, has been found in Microsoft Windows. This issue affects some unknown processing of the component Kernel. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-43520. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43527 | Microsoft Windows 11 24H2 Kernel heap-based overflow
3 months ago
A vulnerability classified as critical has been found in Microsoft Windows 11 24H2. Affected is an unknown function of the component Kernel. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-43527. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43519 | Microsoft Windows up to Server 2022 23H2 WDAC OLE DB Provider for SQL Server numeric truncation error
3 months ago
A vulnerability classified as critical was found in Microsoft Windows. This vulnerability affects unknown code of the component WDAC OLE DB Provider for SQL Server. The manipulation leads to numeric truncation error.
This vulnerability was named CVE-2024-43519. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43526 | Microsoft Windows up to Server 2022 23H2 Mobile Broadband Driver heap-based overflow
3 months ago
A vulnerability was found in Microsoft Windows up to Server 2022 23H2. It has been rated as critical. This issue affects some unknown processing of the component Mobile Broadband Driver. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-43526. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43518 | Microsoft Windows up to Server 2022 23H2 Telephony Server heap-based overflow
3 months ago
A vulnerability classified as critical has been found in Microsoft Windows. This affects an unknown part of the component Telephony Server. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-43518. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43525 | Microsoft Windows up to Server 2022 23H2 Mobile Broadband Driver heap-based overflow
3 months ago
A vulnerability was found in Microsoft Windows up to Server 2022 23H2. It has been declared as critical. This vulnerability affects unknown code of the component Mobile Broadband Driver. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-43525. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43517 | Microsoft Windows up to Server 2022 23H2 ActiveX Data Objects heap-based overflow
3 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component ActiveX Data Objects. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-43517. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
以色列黑入贝鲁特机场塔台,阻止伊朗飞机降落
3 months ago
美国水务巨头遭网络攻击:水计费系统瘫痪,上千万人无法处理账单
3 months ago
公司被迫暂停账单处理服务
CVE-2024-43524 | Microsoft Windows up to Server 2022 23H2 Mobile Broadband Driver range error
3 months ago
A vulnerability was found in Microsoft Windows up to Server 2022 23H2. It has been classified as critical. This affects an unknown part of the component Mobile Broadband Driver. The manipulation leads to range error.
This vulnerability is uniquely identified as CVE-2024-43524. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43516 | Microsoft Windows up to Server 2022 23H2 Secure Kernel Mode untrusted pointer dereference
3 months ago
A vulnerability was found in Microsoft Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Secure Kernel Mode. The manipulation leads to untrusted pointer dereference.
This vulnerability is known as CVE-2024-43516. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com