Aggregator
North Korean hackers create Flutter apps to bypass macOS security
5 months ago
error code: 1106
CVE-2018-9163 | Zoho ManageEngine Recovery Manager Plus up to 5.3 Build 5330 technicianAction.do loginName Stored cross site scripting (EDB-44666 / BID-103773)
5 months ago
A vulnerability was found in Zoho ManageEngine Recovery Manager Plus up to 5.3 Build 5330. It has been classified as problematic. Affected is an unknown function of the file technicianAction.do. The manipulation of the argument loginName leads to cross site scripting (Stored).
This vulnerability is traded as CVE-2018-9163. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Microsoft fixes bugs causing Windows Server 2025 blue screens, install issues
5 months ago
Microsoft has fixed several bugs that cause install, upgrade, and Blue Screen of Death (BSOD) issues on Windows Server 2025 devices with a high core count. [...]
Sergiu Gatlan
How to Combat the CISO Mental Health Crisis - Ram Movva - BSW #372
5 months ago
Nov 12, 2024Stress in cybersecurity is an industrywide problem. The CISOrole is one of the most str
A cyberattack on payment systems blocked cards readers across stores and gas stations in Israel
5 months ago
A cyberattack on payment systems blocked cards readers across stores and gas stations
Ubuntu Security Notice USN-7102-1
5 months ago
==========================================================================Ubuntu Security Notice U
Red Hat Security Advisory 2024-9439-03
5 months ago
The following advisory data is extracted from:https://security.access.redhat.com/data/csaf/v2/advi
Debian Security Advisory 5810-1
5 months ago
-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256- --------------------------------------------------
Red Hat Security Advisory 2024-9333-03
5 months ago
The following advisory data is extracted from:https://security.access.redhat.com/data/csaf/v2/advi
Debian Security Advisory 5811-1
5 months ago
-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA512- --------------------------------------------------
Red Hat Security Advisory 2024-9331-03
5 months ago
The following advisory data is extracted from:https://security.access.redhat.com/data/csaf/v2/advi
Red Hat Security Advisory 2024-9325-03
5 months ago
The following advisory data is extracted from:https://security.access.redhat.com/data/csaf/v2/advi
Trustwave and Cybereason Join Forces to Create a Leading Global MDR Provider, Offering Unmatched Cybersecurity Value
5 months ago
November 12, 2024 2 Minute Read
CVE-2023-39804 | GNU Tar PAX Archive xheader.c locate_handler denial of service
5 months ago
A vulnerability was found in GNU Tar and classified as problematic. Affected by this issue is the function locate_handler of the file xheader.c of the component PAX Archive Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2023-39804. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-31309 | Apache Traffic Server HTTP/2 resource consumption (DLA 3799-1)
5 months ago
A vulnerability was found in Apache Traffic Server and classified as problematic. This issue affects some unknown processing of the component HTTP2 Handler. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2024-31309. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-29007 | Apache CloudStack up to 4.18.1.0/4.19.0.0 HTTP Redirect server-side request forgery
5 months ago
A vulnerability was found in Apache CloudStack up to 4.18.1.0/4.19.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component HTTP Redirect Handler. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2024-29007. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34044 | O-RAN E2T I-Release buildPrometheusList peerInfo null pointer dereference
5 months ago
A vulnerability has been found in O-RAN E2T I-Release and classified as problematic. This vulnerability affects the function buildPrometheusList. The manipulation of the argument peerInfo leads to null pointer dereference.
This vulnerability was named CVE-2024-34044. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-35797 | Linux Kernel up to 6.6.23/6.7.11/6.8.2 cachestat get_shadow_from_swap_cache out-of-bounds
5 months ago
A vulnerability was found in Linux Kernel up to 6.6.23/6.7.11/6.8.2. It has been declared as problematic. Affected by this vulnerability is the function get_shadow_from_swap_cache of the component cachestat. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-35797. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35878 | Linux Kernel up to 6.6.25/6.8.4 vsnprintf len null pointer dereference (e4a449368a2c/544561dc56f7/a1aa5390cc91)
5 months ago
A vulnerability was found in Linux Kernel up to 6.6.25/6.8.4. It has been declared as critical. This vulnerability affects the function vsnprintf. The manipulation of the argument len leads to null pointer dereference.
This vulnerability was named CVE-2024-35878. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com