Aggregator
CVE-2011-2013 | Microsoft Windows 7/Server 2008/Vista TCP/IP Reference Counter numeric error (MS11-083 / EDB-36285)
6 months ago
A vulnerability classified as critical was found in Microsoft Windows 7/Server 2008/Vista. This vulnerability affects unknown code of the component TCP/IP Reference Counter. The manipulation leads to numeric error.
This vulnerability was named CVE-2011-2013. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Fake "Security Alert" issues on GitHub use OAuth app to hijack accounts
6 months ago
A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code. [...]
Lawrence Abrams
CVE-2024-10153 | PHPGurukul Boat Booking System 1.0 Book a Boat Page book-boat.php?bid=1 bookingdatefrom/nopeople sql injection
6 months ago
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file book-boat.php?bid=1 of the component Book a Boat Page. The manipulation of the argument bookingdatefrom/nopeople leads to sql injection.
This vulnerability is known as CVE-2024-10153. The attack can be launched remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2008-2117 | Project Alumni 1.0.9 year cross site scripting (EDB-31724 / XFDB-42149)
6 months ago
A vulnerability was found in Project Alumni 1.0.9. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument year leads to cross site scripting.
This vulnerability was named CVE-2008-2117. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-8690 | Apple iCloud up to 7.12/10.5 on Windows WebKit Universal cross site scripting (HT210357/HT210358 / EDB-47237)
6 months ago
A vulnerability was found in Apple iCloud up to 7.12/10.5 on Windows. It has been rated as problematic. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to cross site scripting (Universal).
This vulnerability is handled as CVE-2019-8690. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-1965 | Microsoft Windows TCP/IP Stack resource management (EDB-17981 / Nessus ID 56044)
6 months ago
A vulnerability was found in Microsoft Windows. It has been classified as critical. Affected is an unknown function of the component TCP/IP Stack. The manipulation leads to improper resource management.
This vulnerability is traded as CVE-2011-1965. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-6817 | IrfanView PSP File Parser out-of-bounds write
6 months ago
A vulnerability was found in IrfanView and classified as critical. This issue affects some unknown processing of the component PSP File Parser. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2024-6817. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-6818 | IrfanView PSP File Parser out-of-bounds write
6 months ago
A vulnerability was found in IrfanView. It has been classified as critical. Affected is an unknown function of the component PSP File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2024-6818. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-6819 | IrfanView PSP File Parser out-of-bounds write
6 months ago
A vulnerability was found in IrfanView. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component PSP File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2024-6819. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-6820 | IrfanView AWD File Parser out-of-bounds write
6 months ago
A vulnerability was found in IrfanView. It has been rated as critical. Affected by this issue is some unknown functionality of the component AWD File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2024-6820. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-6821 | IrfanView CIN File Parser out-of-bounds write
6 months ago
A vulnerability classified as critical has been found in IrfanView. This affects an unknown part of the component CIN File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-6821. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-6703 | techjewel Contact Form Plugin up to 5.1.19 on WordPress description/btn_txt cross site scripting
6 months ago
A vulnerability, which was classified as problematic, has been found in techjewel Contact Form Plugin up to 5.1.19 on WordPress. This issue affects some unknown processing. The manipulation of the argument description/btn_txt leads to cross site scripting.
The identification of this vulnerability is CVE-2024-6703. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6822 | IrfanView CIN File Parser out-of-bounds write
6 months ago
A vulnerability classified as critical was found in IrfanView. This vulnerability affects unknown code of the component CIN File Parser. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-6822. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
AI vs Human CTF Challenge
6 months ago
Name: AI vs Human CTF Challenge (an AI vs Human CTF event.)
Date: March 14, 2025, 3 p.m. — 16 March 2025, 15:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.hackthebox.com/event/details/ai-vs-human-ctf-challenge-2000
Rating weight: 0.00
Event organizers: Palisade Research
Date: March 14, 2025, 3 p.m. — 16 March 2025, 15:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.hackthebox.com/event/details/ai-vs-human-ctf-challenge-2000
Rating weight: 0.00
Event organizers: Palisade Research
@Hack 2025
6 months ago
Name: @Hack 2025 (an @Hack event.)
Date: March 15, 2025, 11 a.m. — 16 March 2025, 11:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Canada, Montreal
Offical URL: https://2025.athackctf.com/
Rating weight: 0.00
Event organizers: AthackPrivate
Date: March 15, 2025, 11 a.m. — 16 March 2025, 11:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Canada, Montreal
Offical URL: https://2025.athackctf.com/
Rating weight: 0.00
Event organizers: AthackPrivate
K!nd4SUS CTF 2025
6 months ago
Name: K!nd4SUS CTF 2025 (an K!nd4SUS CTF event.)
Date: March 15, 2025, 1 p.m. — 16 March 2025, 13:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.k1nd4sus.it/
Rating weight: 19.02
Event organizers: K!nd4SUS
Date: March 15, 2025, 1 p.m. — 16 March 2025, 13:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.k1nd4sus.it/
Rating weight: 19.02
Event organizers: K!nd4SUS
Nowruz 1404
6 months ago
Name: Nowruz 1404 (an FMCTF event.)
Date: March 15, 2025, 1:30 p.m. — 16 March 2025, 13:30 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://1404.fmc.tf/
Rating weight: 24.51
Event organizers: FlagMotori
Date: March 15, 2025, 1:30 p.m. — 16 March 2025, 13:30 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://1404.fmc.tf/
Rating weight: 24.51
Event organizers: FlagMotori
RansomHub
6 months ago
cohenido
Welcome to Security Week 2025
6 months ago
Over the next week, we will discuss the latest trends in cyber security, announce new products and partnerships, and showcase the latest in Cloudflare technology. Welcome to Security Week 2025!
Grant Bourzikas