Aggregator
Life at SpecterOps Part II: From Dream to Reality
7 months 3 weeks ago
Duane Michael
CVE-2024-31981 | XWiki xwiki-platform-oldcore PDFClass authorization
7 months 3 weeks ago
A vulnerability classified as critical has been found in XWiki xwiki-platform-oldcore. This affects an unknown part of the component PDFClass Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-31981. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-31986 | XWiki xwiki-platform-scheduler-ui Scheduler Job cross-site request forgery
7 months 3 weeks ago
A vulnerability was found in XWiki xwiki-platform-scheduler-ui and classified as problematic. Affected by this issue is some unknown functionality of the component Scheduler Job. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-31986. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-31987 | XWiki xwiki-platform-oldcore Custom Skins Support authorization
7 months 3 weeks ago
A vulnerability was found in XWiki xwiki-platform-oldcore. It has been classified as critical. This affects an unknown part of the component Custom Skins Support. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-31987. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-2966 | bdthemes Element Pack Elementor Addons Plugin up to 5.5.6 on WordPress element_pack_ajax_search information disclosure (ID 3066178)
7 months 3 weeks ago
A vulnerability was found in bdthemes Element Pack Elementor Addons Plugin up to 5.5.6 on WordPress. It has been rated as problematic. This issue affects the function element_pack_ajax_search. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-2966. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-3875 | Tenda F1202 1.2.0.20(408) /goform/Natlimit fromNatlimit page stack-based overflow
7 months 3 weeks ago
A vulnerability was found in Tenda F1202 1.2.0.20(408). It has been rated as critical. This issue affects the function fromNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-3875. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-3876 | Tenda F1202 1.2.0.20(408) /goform/VirtualSer fromVirtualSer page stack-based overflow
7 months 3 weeks ago
A vulnerability classified as critical has been found in Tenda F1202 1.2.0.20(408). Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2024-3876. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-3877 | Tenda F1202 1.2.0.20(408) /goform/fromqossetting qos stack-based overflow
7 months 3 weeks ago
A vulnerability classified as critical was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function fromqossetting of the file /goform/fromqossetting. The manipulation of the argument qos leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-3877. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-3878 | Tenda F1202 1.2.0.20(408) webExcptypemanFilter fromwebExcptypemanFilter page stack-based overflow
7 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Tenda F1202 1.2.0.20(408). Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2024-3878. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-34717 | PrestaShop 8.1.5 secure_key information disclosure
7 months 3 weeks ago
A vulnerability classified as problematic has been found in PrestaShop 8.1.5. Affected is an unknown function. The manipulation of the argument secure_key leads to information disclosure.
This vulnerability is traded as CVE-2024-34717. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
New Mirai botnet variant Murdoc Botnet targets AVTECH IP cameras and Huawei HG532 routers
7 months 3 weeks ago
Researchers warn of a campaign exploiting AVTECH IP cameras and Huawei HG532 routers to create a Mirai botnet variant called Murdoc Botnet. Murdoc Botnet is a new Mirai botnet variant that targets vulnerabilities in AVTECH IP cameras and Huawei HG532 routers, the Qualys Threat Research Unit reported. The botnet has been active since at least […]
Pierluigi Paganini
Injectra: A Python Tool for Seamlessly Injecting Custom Payloads into Files Using Magic Numbers
7 months 3 weeks ago
Injectra: A Python Tool for Seamlessly Injecting Custom Payloads into Files Using Magic Numbers
Dark Web Informer - Cyber Threat Intelligence
Экзоскелет для маэстро: робот Sony помогает пианистам достичь невозможного
7 months 3 weeks ago
Компания нашла способ обмануть законы природы.
CVE-2009-0130 | OpenSSL crypto_drv.c DSA_do_verify improper authentication (Nessus ID 35310)
7 months 3 weeks ago
A vulnerability classified as problematic has been found in OpenSSL. This affects the function DSA_do_verify in the library lib/crypto/c_src/crypto_drv.c. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2009-0130. It is possible to initiate the attack remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-0554 | Microsoft Internet Explorer 5.01 SP4/6 SP1/7 resource management (EDB-8479 / Nessus ID 36152)
7 months 3 weeks ago
A vulnerability was found in Microsoft Internet Explorer 5.01 SP4/6 SP1/7. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper resource management.
This vulnerability is traded as CVE-2009-0554. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-1936 | cpCommerce up to 1.2.9 functions.php GLOBALS[prefix] path traversal (EDB-8790 / BID-35103)
7 months 3 weeks ago
A vulnerability was found in cpCommerce up to 1.2.9. It has been rated as critical. This issue affects some unknown processing of the file functions.php. The manipulation of the argument GLOBALS[prefix] leads to path traversal.
The identification of this vulnerability is CVE-2009-1936. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1532 | Microsoft Internet Explorer up to 8 Row Reference resource management (MS09-019 / EDB-33024)
7 months 3 weeks ago
A vulnerability classified as critical has been found in Microsoft Internet Explorer up to 8. This affects an unknown part of the component Row Reference Handler. The manipulation leads to improper resource management.
This vulnerability is uniquely identified as CVE-2009-1532. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-2416 | XMLSoft libxml up to 2.6.32 resource management (Nessus ID 41557 / ID 155825)
7 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in XMLSoft libxml up to 2.6.32. Affected is an unknown function. The manipulation leads to improper resource management.
This vulnerability is traded as CVE-2009-2416. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2009-2494 | Microsoft Windows Server 2003 code injection (EDB-9108 / Nessus ID 40556)
7 months 3 weeks ago
A vulnerability, which was classified as very critical, has been found in Microsoft Windows Server 2003. Affected by this issue is some unknown functionality. The manipulation leads to code injection.
This vulnerability is handled as CVE-2009-2494. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com