Aggregator
Kimsuky-linked hackers use similar tactics to attack Russia and South Korea, researchers say
9 months 1 week ago
The threat actor known as Konni, which has been previously linked to the North Korean state-sponsor
第四届“长城杯”网络安全大赛暨京津冀网络安全技能竞赛(初赛)by Mini-Venom
9 months 1 week ago
CVE-2007-2485 | Ruben Boelinger myflash 1.00 on WordPress myflash-button.php wpPATH file inclusion (EDB-3828 / XFDB-34000)
9 months 1 week ago
A vulnerability classified as critical has been found in Ruben Boelinger myflash 1.00 on WordPress. Affected is an unknown function of the file myflash-button.php. The manipulation of the argument wpPATH leads to file inclusion.
This vulnerability is traded as CVE-2007-2485. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-20123, CVE-2021-20124: DrayTek Vulnerabilities Discovered by Tenable Research Added to CISA KEV
9 months 1 week ago
苹果可能会结束EarPods有线耳机的历史 不再继续生产此类有线耳机
9 months 1 week ago
AI 时代首款 iPhone 发布,意味着 AiPhone 时代到来了吗?
9 months 1 week ago
iPhone 16 的发布,意味着苹果迈入 AiPhone 时代。
Official: DHS cyber review board will announce next investigation ‘soon’
9 months 1 week ago
A review board of federal and industry officials led by the Homeland Security Department is readyin
谛听 工控安全月报 | 8月
9 months 1 week ago
8月│月报 谛听工控安全月报上线了,工信部的最新政策,8月发生的多起工控安全事件,谛听团队收集的最新攻击教据......更多安全资讯,请关注“谛听ditecting",每月更新!
谛听 工控安全月报 | 8月
9 months 1 week ago
8月│月报 谛听工控安全月报上线了,工信部的最新政策,8月发生的多起工控安全事件,谛听团队收集的最新攻击教据......更多安全资讯,请关注“谛听ditecting",每月更新!
CVE-2022-39172 | mb Support openVIVA prior 20220801 Vorgang Name/Hauptverantwortlicher cross site scripting
9 months 1 week ago
A vulnerability was found in mb Support openVIVA. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Vorgang Handler. The manipulation of the argument Name/Hauptverantwortlicher leads to cross site scripting.
This vulnerability is known as CVE-2022-39172. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-40130 | Google Android CallRedirectionProcessor.java onBindingDied permission
9 months 1 week ago
A vulnerability was found in Google Android and classified as critical. This issue affects the function onBindingDied of the file CallRedirectionProcessor.java. The manipulation leads to permission issues.
The identification of this vulnerability is CVE-2023-40130. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-46570 | radare2 up to 5.8.9 nds32-dis.h print_insn32 out-of-bounds (Issue 22333)
9 months 1 week ago
A vulnerability classified as problematic has been found in radare2 up to 5.8.9. This affects the function print_insn32 in the library libr/arch/p/nds32/nds32-dis.h. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2023-46570. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-46569 | radare2 up to 5.8.9 nds32-dis.h print_insn32_fpu out-of-bounds (Issue 22334)
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in radare2 up to 5.8.9. This issue affects the function print_insn32_fpu in the library libr/arch/p/nds32/nds32-dis.h. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2023-46569. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-40140 | Google Android android_view_InputDevice.cpp android_view_InputDevice_create use after free
9 months 1 week ago
A vulnerability classified as problematic has been found in Google Android. Affected is the function android_view_InputDevice_create of the file android_view_InputDevice.cpp. The manipulation leads to use after free.
This vulnerability is traded as CVE-2023-40140. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-46866 | International Color Consortium DemoIccMAX 79ecb74 IccProfLib/IccTagLut.cpp CIccCLUT::Interp3d out-of-bounds (Issue 54)
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in International Color Consortium DemoIccMAX 79ecb74. Affected by this issue is the function CIccCLUT::Interp3d in the library IccProfLib/IccTagLut.cpp. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2023-46866. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-46867 | International Color Consortium DemoIccMAX 79ecb74 IccCmm.cpp GetCurve null pointer dereference (Issue 54)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in International Color Consortium DemoIccMAX 79ecb74. This affects the function CIccXformMatrixTRC::GetCurve of the file IccCmm.cpp. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2023-46867. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-47101 | Securepoint SSL VPN Client 2.0.28/2.0.32 Installer Local Privilege Escalation (CYADV-2023-012)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in Securepoint SSL VPN Client 2.0.28/2.0.32. This affects an unknown part of the component Installer. The manipulation leads to Local Privilege Escalation.
This vulnerability is uniquely identified as CVE-2023-47101. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-47104 | tinyfiledialogs up to 3.14.x os command injection (ac9f9f6d)
9 months 1 week ago
A vulnerability was found in tinyfiledialogs up to 3.14.x. It has been classified as critical. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2023-47104. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-36767 | tinyfiledialogs up to 3.7.x os command injection (Issue 25498)
9 months 1 week ago
A vulnerability was found in tinyfiledialogs up to 3.7.x. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to os command injection.
This vulnerability is known as CVE-2020-36767. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com