Aggregator
史上首例:NPM包Nx被投毒,开发人员遭AI软件供应链攻击
5 months 2 weeks ago
这是有史以来恶意软件胁迫AI助手CLI协助侦查的首个案例。
CVE-2025-9674 | Transbyte Scooper News App up to 1.2 on Android com.hatsune.eagleee AndroidManifest.xml improper export of android application components
5 months 2 weeks ago
A vulnerability identified as problematic has been detected in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export of android application components.
This vulnerability appears as CVE-2025-9674. The attack requires local access. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9673 | Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android com.kakao.i.connect AndroidManifest.xml improper export of android application components
5 months 2 weeks ago
A vulnerability categorized as problematic has been discovered in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android application components.
This vulnerability is reported as CVE-2025-9673. The attack requires a local approach. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9672 | Rejseplanen App up to 8.2.2 de.hafas.android.rejseplanen AndroidManifest.xml improper export of android application components
5 months 2 weeks ago
A vulnerability was found in Rejseplanen App up to 8.2.2. It has been rated as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejseplanen. The manipulation leads to improper export of android application components.
This vulnerability is documented as CVE-2025-9672. The attack needs to be performed locally. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9671 | UAB Paytend App up to 2.1.9 on Android com.passport.cash AndroidManifest.xml improper export of android application components
5 months 2 weeks ago
A vulnerability was found in UAB Paytend App up to 2.1.9 on Android. It has been declared as problematic. This impacts an unknown function of the file AndroidManifest.xml of the component com.passport.cash. Executing manipulation can lead to improper export of android application components.
This vulnerability is registered as CVE-2025-9671. The attack needs to be launched locally. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #638068: Transbyte App Scooper News: Local To Globa(com.hatsune.eagleee) 1.2 Task Hijacking [Accepted]
5 months 2 weeks ago
Submit #638068 / VDB-321884
fxizenta
Submit #637925: Kakao Corp. Hey Kakao(com.kakao.i.connect) 2.17.4 Task Hijacking [Accepted]
5 months 2 weeks ago
Submit #637925 / VDB-321883
fxizenta
Submit #637924: Rejseplanen Rejseplanen(de.hafas.android.rejseplanen) 8.2.2(141) Task Hijacking [Accepted]
5 months 2 weeks ago
Submit #637924 / VDB-321882
fxizenta
顶会入选 | 全密态机器学习之安全数据对齐—Suda 框架入选 USENIX Security 2025
5 months 2 weeks ago
如何高效对齐数据而不泄露任何隐私
Submit #637922: UAB "PAYTEND EUROPE" Paytend 2.1.9 Task Hijacking [Accepted]
5 months 2 weeks ago
Submit #637922 / VDB-321881
fxizenta
CVE-2025-9670 | mixmark-io turndown up to 7.2.1 src/commonmark-rules.js redos (Issue 501)
5 months 2 weeks ago
A vulnerability was found in mixmark-io turndown up to 7.2.1. It has been classified as problematic. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity.
This vulnerability is cataloged as CVE-2025-9670. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
速修复Passwordstate 中的这个认证绕过漏洞
5 months 2 weeks ago
速修复
思科 Nexus 交换机中存在高危DoS 漏洞
5 months 2 weeks ago
速修复
开创多元协同治理格局 促进人工智能安全有序发展
5 months 2 weeks ago
360披露银狐木马最新攻击链: 通过GAC劫持实现全局程序控制
5 months 2 weeks ago
银狐木马新变种利用GAC特性劫持系统,360安全智能体实现自动阻断
再添数字政府新名片!深圳“深治慧”平台入选2025数博会创新案例
5 months 2 weeks ago
智能体驱动,360助力深圳打造数字政府新标杆
即刻揭晓!8项长亭科技「特色业务场景解决方案」
5 months 2 weeks ago
强势围观!
Submit #637911: turndown npm v7.2.1 Inefficient Regular Expression Complexity [Accepted]
5 months 2 weeks ago
Submit #637911 / VDB-321880
CrazzyHe
CVE-2025-7383 | Oberon PSA Crypto up to 1.5.0 timing discrepancy
5 months 2 weeks ago
A vulnerability was found in Oberon PSA Crypto up to 1.5.0 and classified as problematic. The impacted element is an unknown function. Such manipulation leads to observable timing discrepancy.
This vulnerability is listed as CVE-2025-7383. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com