Aggregator
Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks
1 month 1 week ago
A critical heap buffer overflow vulnerability has been discovered in the source code of NGINX, present since 2008. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution (RCE) against one of the most widely used web servers in the world. Assigned a CVSS score of […]
The post Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News.
Abinaya
流媒体Netflix的广告野心还在不断增长
1 month 1 week ago
Netflix的广告支持套餐连续第二年月活跃人数增长了一倍以上。在2026年的广告预售会中,Netflix透露,其每月8.99美元的套餐覆盖全球超过 2.5亿人,较去年报告的9400万用户有显著跃升。
Nitrogen Ransomware claims massive data theft from Foxconn
1 month 1 week ago
Nitrogen Ransomware claims massive data theft from FoxconnFoxco
Nitrogen Ransomware claims massive data theft from Foxconn
1 month 1 week ago
Foxconn confirmed a cyberattack on some North American factories. The Nitrogen ransomware group claims it stole 8TB of data from the firm. Foxconn confirmed that several of its North American factories were affected by a cyberattack. The manufacturer confirmed it was targeted by threat actors after the Nitrogen ransomware group listed it on its Tor […]
Pierluigi Paganini
Gli uomini possono fare tutto (Maggio 2026)
1 month 1 week ago
E' vero che, fortunatamente, in molti ambienti sono ampiamente accettate modifiche agli incontri a
Reverse Engineering Slither.io’s Network Protocol
1 month 1 week ago
CVE-2016-6253 | NetBSD up to 7.0.1 /usr/libexec/mail.local link following (NetBSD-SA2016-006 / EDB-40141)
1 month 1 week ago
A vulnerability categorized as problematic has been discovered in NetBSD up to 7.0.1. The impacted element is an unknown function in the library /usr/libexec/mail.local. Executing a manipulation can lead to link following.
This vulnerability is handled as CVE-2016-6253. It is possible to launch the attack on the local host. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2016-8213 | EMC Documentum Webtop/TaskSpace/Capital Projects 6.8 cross site scripting (ESA-2016-143 / BID-95625)
1 month 1 week ago
A vulnerability labeled as problematic has been found in EMC Documentum Webtop, TaskSpace and Capital Projects 6.8. Affected by this vulnerability is an unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2016-8213. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2016-5323 | LibTIFF up to 4.0.5 _TIFFFax3fillruns divide by zero (Nessus ID 93322 / ID 169468)
1 month 1 week ago
A vulnerability labeled as problematic has been found in LibTIFF up to 4.0.5. Affected by this issue is the function _TIFFFax3fillruns. Such manipulation leads to divide by zero.
This vulnerability is documented as CVE-2016-5323. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2016-9435 | w3m up to 0.5.3 dd Tag file.c HTMLtagproc1 input validation (Nessus ID 95650 / ID 169423)
1 month 1 week ago
A vulnerability marked as problematic has been reported in w3m up to 0.5.3. This affects the function HTMLtagproc1 of the file file.c of the component dd Tag Handler. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2016-9435. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2016-9436 | w3m up to 0.5.3 i Tag parsetagx.c input validation (Nessus ID 95650 / ID 169423)
1 month 1 week ago
A vulnerability described as problematic has been identified in w3m up to 0.5.3. This vulnerability affects unknown code of the file parsetagx.c of the component i Tag Handler. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2016-9436. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2017-5545 | libimobiledevice up to 1.12 Apple Property List Data plistutil.c main out-of-bounds (Nessus ID 96910 / ID 169744)
1 month 1 week ago
A vulnerability classified as critical has been found in libimobiledevice up to 1.12. This issue affects the function main of the file plistutil.c of the component Apple Property List Data Handler. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2017-5545. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-10101 | Hitek Automize 10.x/11.x passManager.jsd inadequate encryption (BID-96840)
1 month 1 week ago
A vulnerability labeled as problematic has been found in Hitek Automize 10.x/11.x. The impacted element is an unknown function of the file passManager.jsd. The manipulation results in inadequate encryption strength.
This vulnerability is cataloged as CVE-2016-10101. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2016-10102 | Hitek Automize up to 10.25/11.14 Profile Password hitek.jar inadequate encryption (BID-96848)
1 month 1 week ago
A vulnerability marked as critical has been reported in Hitek Automize up to 10.25/11.14. This affects an unknown function of the file hitek.jar of the component Profile Password Handler. This manipulation causes inadequate encryption strength.
This vulnerability is registered as CVE-2016-10102. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2016-10103 | Hitek Automize up to 10.25/11.14 GPG Encryption Profile encryptionProfiles.jsd inadequate encryption (BID-96850)
1 month 1 week ago
A vulnerability described as problematic has been identified in Hitek Automize up to 10.25/11.14. This impacts an unknown function of the file encryptionProfiles.jsd of the component GPG Encryption Profile Handler. Such manipulation leads to inadequate encryption strength.
This vulnerability is documented as CVE-2016-10103. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2016-10104 | Hitek Automize up to 10.25/11.14 sshProfiles.jsd Password inadequate encryption (BID-96845)
1 month 1 week ago
A vulnerability classified as problematic has been found in Hitek Automize up to 10.25/11.14. Affected is an unknown function of the file sshProfiles.jsd. Performing a manipulation results in inadequate encryption strength (Password).
This vulnerability is reported as CVE-2016-10104. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2016-10156 | systemd v228 Timer /src/basic/fs-util.c access control (EDB-41171 / Nessus ID 96793)
1 month 1 week ago
A vulnerability classified as critical was found in systemd v228. Affected by this vulnerability is an unknown functionality of the file /src/basic/fs-util.c of the component Timer Handler. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2016-10156. The attack requires local access. In addition, an exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2016-10157 | Akamai NetSession 1.9.3.1 CSUNSAPI.dll code injection (ID 140366 / BID-95995)
1 month 1 week ago
A vulnerability, which was classified as critical, has been found in Akamai NetSession 1.9.3.1. Affected by this issue is some unknown functionality in the library CSUNSAPI.dll. The manipulation leads to code injection.
This vulnerability is traded as CVE-2016-10157. An attack has to be approached locally. There is no exploit available.
vuldb.com
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)
1 month 1 week ago
Besides serving as a place where Microsoft Outlook places suspected spam, the Outlook Junk folder h