Aggregator
CVE-2011-4280 | Moodle 2.0/2.0.1 cross site scripting (EDB-35297)
8 months 4 weeks ago
A vulnerability was found in Moodle 2.0/2.0.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2011-4280. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
BellaCPP, Charming Kitten’s BellaCiao variant written in C++
8 months 4 weeks ago
Iran-linked APT group Charming Kitten has been observed using a new variant of the BellaCiao malware dubbed BellaCPP, Kaspersky researchers warn. The Iran-linked APT group Charming Kitten has been observed using a C++ variant of the BellaCiao malware, dubbed BellaCPP. BellaCiao, a .NET-based malware, combines webshell persistence with covert tunneling. The malicious code was first […]
Pierluigi Paganini
CVE-2017-5638 | Oracle Financial Services Profitability Management up to 8.0.4 Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability, which was classified as very critical, was found in Oracle Financial Services Profitability Management up to 8.0.4. Affected is an unknown function of the component Struts 2. The manipulation leads to handling of exceptional conditions.
This vulnerability is traded as CVE-2017-5638. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Reconciliation Framework 8.0.0/8.0.1/8.0.2 Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability has been found in Oracle Financial Services Reconciliation Framework 8.0.0/8.0.1/8.0.2 and classified as very critical. Affected by this vulnerability is an unknown functionality of the component Struts 2. The manipulation leads to handling of exceptional conditions.
This vulnerability is known as CVE-2017-5638. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Hedge Management 6.1.1/8.0.1/8.0.2/8.0.3/8.0.4 Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability was found in Oracle Financial Services Hedge Management and IFRS Valuations 6.1.1/8.0.1/8.0.2/8.0.3/8.0.4. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component Struts 2. The manipulation leads to handling of exceptional conditions.
This vulnerability is known as CVE-2017-5638. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Institutional Performance Analytics Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability was found in Oracle Financial Services Institutional Performance Analytics 8.0.0 to 8.0.4. It has been rated as very critical. Affected by this issue is some unknown functionality of the component Struts 2. The manipulation leads to handling of exceptional conditions.
This vulnerability is handled as CVE-2017-5638. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4 Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability classified as very critical has been found in Oracle Financial Services Liquidity Risk Management 8.0.1/8.0.2/8.0.4. This affects an unknown part of the component Struts 2. The manipulation leads to handling of exceptional conditions.
This vulnerability is uniquely identified as CVE-2017-5638. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Loan Loss Forecasting up to 8.0.4 Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability classified as very critical was found in Oracle Financial Services Loan Loss Forecasting and Provisioning up to 8.0.4. This vulnerability affects unknown code of the component Struts 2. The manipulation leads to handling of exceptional conditions.
This vulnerability was named CVE-2017-5638. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Pricing Management 8.0.0 to 8.0.4 Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability, which was classified as very critical, has been found in Oracle Financial Services Pricing Management and Transfer Pricing Component 8.0.0 to 8.0.4. This issue affects some unknown processing of the component Struts 2. The manipulation leads to handling of exceptional conditions.
The identification of this vulnerability is CVE-2017-5638. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Enterprise Financial Performance Analytics Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability was found in Oracle Financial Services Enterprise Financial Performance Analytics 8.0.0 to 8.0.4 and classified as very critical. This issue affects some unknown processing of the component Struts 2. The manipulation leads to handling of exceptional conditions.
The identification of this vulnerability is CVE-2017-5638. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-5638 | Oracle Financial Services Funds Transfer Pricing up to 8.0.4 Struts 2 exceptional condition (VU#834067 / EDB-41570)
8 months 4 weeks ago
A vulnerability was found in Oracle Financial Services Funds Transfer Pricing up to 8.0.4. It has been classified as very critical. Affected is an unknown function of the component Struts 2. The manipulation leads to handling of exceptional conditions.
This vulnerability is traded as CVE-2017-5638. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-3859 | Microsoft Office 2010 Chinese IME access control (MS13-075 / kb2687413)
8 months 4 weeks ago
A vulnerability classified as critical has been found in Microsoft Office 2010. Affected is an unknown function of the component Chinese IME. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2013-3859. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-3843 | Monkey HTTP Daemon up to 1.1.1 mk_request.c mk_request_header_process memory corruption (Issue 182 / Nessus ID 70129)
8 months 4 weeks ago
A vulnerability was found in Monkey HTTP Daemon up to 1.1.1. It has been declared as critical. This vulnerability affects the function mk_request_header_process of the file mk_request.c. The manipulation leads to memory corruption.
This vulnerability was named CVE-2013-3843. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-3868 | Microsoft Windows 7/8/Server 2008/Vista Active Directory input validation (MS13-079 / KB2853587)
8 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows 7/8/Server 2008/Vista. Affected by this issue is some unknown functionality of the component Active Directory. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2013-3868. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-3863 | Microsoft Windows Server 2003/XP OLE Object memory corruption (MS13-070 / Nessus ID 69830)
8 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Windows Server 2003/XP. This affects an unknown part of the component OLE Object Handler. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2013-3863. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-3862 | Microsoft Windows 7/Server 2008 R2 Service Control Manager resource management (MS13-077 / KB2872339)
8 months 4 weeks ago
A vulnerability was found in Microsoft Windows 7/Server 2008 R2 and classified as critical. This issue affects some unknown processing of the component Service Control Manager. The manipulation leads to improper resource management.
The identification of this vulnerability is CVE-2013-3862. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-3870 | Microsoft Outlook 2007/2010 S/MIME resource management (MS13-068 / kb2825999/kb2794707)
8 months 4 weeks ago
A vulnerability classified as critical was found in Microsoft Outlook 2007/2010. Affected by this vulnerability is an unknown functionality of the component S/MIME Handler. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2013-3870. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-3869 | Microsoft Windows up to XP X.509 Certificate Processor Crypt32.dll/Wcrypt32.dll input validation (MS13-095 / Nessus ID 70853)
8 months 4 weeks ago
A vulnerability was found in Microsoft Windows up to XP and classified as problematic. This issue affects some unknown processing in the library Crypt32.dll/Wcrypt32.dll of the component X.509 Certificate Processor. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2013-3869. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-0455 | unilogies bumsys up to 1.0.2 unrestricted upload (EDB-51492)
8 months 4 weeks ago
A vulnerability classified as critical was found in unilogies bumsys up to 1.0.2. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2023-0455. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com