Aggregator
FIGHTER BLACKHAT CYBER CRIME Targeted the Website of Elbit Systems
CVE-2024-50202 | Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4 nilfs_find_entry exceptional condition (Nessus ID 212993)
8 months 4 weeks ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4. This affects the function nilfs_find_entry. The manipulation leads to handling of exceptional conditions.
This vulnerability is uniquely identified as CVE-2024-50202. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47712 | Linux Kernel up to 6.11.1 wilc1000 wilc_parse_join_bss_param use after free (Nessus ID 212998)
8 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 6.11.1 and classified as critical. This issue affects the function wilc_parse_join_bss_param of the component wilc1000. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-47712. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47718 | Linux Kernel up to 6.11.1 rtw88 rtw_wait_firmware_completion use after free (Nessus ID 212995)
8 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.11.1. This issue affects the function rtw_wait_firmware_completion of the component rtw88. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-47718. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-27372 | SPIP up to 3.2.17/4.0.9/4.1.7/4.2.0 Form Value deserialization (EDB-51536)
8 months 4 weeks ago
A vulnerability classified as critical was found in SPIP up to 3.2.17/4.0.9/4.1.7/4.2.0. This vulnerability affects unknown code of the component Form Value Handler. The manipulation leads to deserialization.
This vulnerability was named CVE-2023-27372. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50160 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 cs8409 snd_hda_gen_add_kctl null pointer dereference (Nessus ID 213001)
8 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. It has been rated as problematic. Affected by this issue is the function snd_hda_gen_add_kctl of the component cs8409. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-50160. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50201 | Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4 radeon initialization (Nessus ID 212999)
8 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component radeon. The manipulation leads to improper initialization.
This vulnerability is handled as CVE-2024-50201. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50205 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 ALSA apply_constraint_to_size divide by zero (Nessus ID 213002)
8 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 and classified as problematic. This issue affects the function apply_constraint_to_size of the component ALSA. The manipulation leads to divide by zero.
The identification of this vulnerability is CVE-2024-50205. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-2881 | wolfSSL up to 5.6.6 on Linux wolfCrypt ed25519.c in wc_ed25519_sign_msg Rowhammer improper restriction of software interfaces to hardware features (Nessus ID 213003)
8 months 4 weeks ago
A vulnerability has been found in wolfSSL up to 5.6.6 on Linux and classified as critical. Affected by this vulnerability is the function in wc_ed25519_sign_msg of the file wolfssl/wolfcrypt/src/ed25519.c of the component wolfCrypt. The manipulation leads to improper restriction of software interfaces to hardware features.
This vulnerability is known as CVE-2024-2881. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Hacker Uses Info-Stealer Against Security Pros, Other Bad Actors
8 months 4 weeks ago
An unknown hacker called MUT-1244 used information-stealing malware to not only grab sensitive data from cybersecurity professionals but also to steal WordPress credentials from other bad actors who had bought them on the dark web.
The post Hacker Uses Info-Stealer Against Security Pros, Other Bad Actors appeared first on Security Boulevard.
Jeffrey Burt
RansomHub
8 months 4 weeks ago
cohenido
RansomHub
8 months 4 weeks ago
cohenido
DEF CON 32 – Cultivating M4D SK1LLZ In the DEF CON Community
8 months 4 weeks ago
Authors/Presenters: Yan Shoshitaishvili, Perri Adams
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Cultivating M4D SK1LLZ In the DEF CON Community appeared first on Security Boulevard.
Marc Handelman
390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits
8 months 4 weeks ago
A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled the exfiltration of over 390,000 credentials.
The malicious activity is part of a broader attack campaign undertaken by a threat actor, dubbed MUT-1244 (where MUT refers to "mysterious unattributed threat") by Datadog Security Labs, that
The Hacker News
CVE-2024-52836 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
8 months 4 weeks ago
A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.5.21. This affects an unknown part of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-52836. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52842 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
8 months 4 weeks ago
A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.5.21. This vulnerability affects unknown code of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-52842. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52841 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
8 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Adobe Experience Manager up to 6.5.21. This issue affects some unknown processing of the component Form Field Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-52841. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52843 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
8 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Adobe Experience Manager up to 6.5.21. Affected is an unknown function of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-52843. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52845 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
8 months 4 weeks ago
A vulnerability has been found in Adobe Experience Manager up to 6.5.21 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-52845. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52834 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
8 months 4 weeks ago
A vulnerability was found in Adobe Experience Manager up to 6.5.21 and classified as problematic. Affected by this issue is some unknown functionality of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-52834. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com