Aggregator
CVE-2019-8646 | Apple watchOS up to 5.2.1 Siri out-of-bounds (HT210353 / EDB-47194)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Apple watchOS up to 5.2.1. Affected by this issue is some unknown functionality of the component Siri. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2019-8646. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4451 | WikkaWiki 1.3.1/1.3.2 Logging (ID 1098 / EDB-18177)
1 year 3 months ago
A vulnerability classified as problematic has been found in WikkaWiki 1.3.1/1.3.2. This affects an unknown part of the component Logging. The manipulation leads to an unknown weakness.
This vulnerability is uniquely identified as CVE-2011-4451. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
vuldb.com
Cisco warns of a ClamAV bug with PoC exploit
1 year 3 months ago
Cisco warns of a ClamAV bug with PoC exploitCisco addressed a C
Cisco warns of a ClamAV bug with PoC exploit
1 year 3 months ago
Cisco addressed a ClamAV denial-of-service (DoS) vulnerability, and experts warn of the availability of a proof-of-concept (PoC) exploit code. Cisco has released security updates to address a ClamAV denial-of-service (DoS) vulnerability tracked as CVE-2025-20128. The Cisco PSIRT experts warn of the availability of a proof-of-concept (PoC) exploit code for this flaw. The vulnerability resides in […]
Pierluigi Paganini
CVE-2019-8646 | Apple watchOS up to 5.2.1 Core Data out-of-bounds (HT210353 / EDB-47194)
1 year 3 months ago
A vulnerability classified as critical has been found in Apple watchOS up to 5.2.1. This affects an unknown part of the component Core Data. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2019-8646. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
喜欢,简单,长期
1 year 3 months ago
看到有朋友转发科比的访谈,提到为什么要四点开始训练:You wake up at 3, train at 4. 4-6. Come home, eat breakfast, relax. Now yo
喜欢,简单,长期
1 year 3 months ago
水滴石穿、愚公移山、磨杵成针……有不少成语都表达了“持之以恒地做一件事,最终能达到目标”,不过它们都忽略了起点“喜欢”,也忽略了很有技术含量的一件事“找到可以简单执行的方法”。
CVE-2007-6041 | Rigs Of Rogs up to 0.x sequencer.cpp sequencer::queuemessage memory corruption (EDB-30779 / XFDB-38549)
1 year 3 months ago
A vulnerability was found in Rigs Of Rogs up to 0.x and classified as critical. This issue affects the function sequencer::queuemessage of the file sequencer.cpp. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2007-6041. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4452 | WikkaWiki 1.3.1/1.3.2 cross-site request forgery (ID 1819 / EDB-18177)
1 year 3 months ago
A vulnerability classified as problematic was found in WikkaWiki 1.3.1/1.3.2. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2011-4452. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
网络安全周报第508期:国际版
1 year 3 months ago
本期《网络安全周报》揭示汽车、企业网络及云服务漏洞,勒索软件滥用Office 365,DDoS攻击创纪录,网络安全威胁持续升级,防御迫在眉睫。
CVE-2020-8947 | Artica Pandora FMS 7.0 functions_netflow.php Shell Metacharacter os command injection (ID 156326 / EDB-48064)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Artica Pandora FMS 7.0. This affects an unknown part of the file functions_netflow.php. The manipulation as part of Shell Metacharacter leads to os command injection.
This vulnerability is uniquely identified as CVE-2020-8947. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
FreeBuf早报 | 这些“春节福利”都是诈骗陷阱;思科警告ClamAV漏洞出现PoC利用代码
1 year 3 months ago
一个叫“五行红包”的App谎称与国家合作发放“红包”补贴,在用户进行所谓的“提现”操作过程中,窃取用户隐私。
时隔800天,万能任务栏工具 TrafficMonitor 居然更新了
1 year 3 months ago
CVE-2010-0611 | Baalsystems Baal Systems up to 3.8 adminlogin.php sql injection (EDB-11346 / XFDB-56147)
1 year 3 months ago
A vulnerability classified as critical was found in Baalsystems Baal Systems up to 3.8. Affected by this vulnerability is an unknown functionality of the file adminlogin.php. The manipulation leads to sql injection.
This vulnerability is known as CVE-2010-0611. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.
vuldb.com
CVE-2015-2067 | magmi Server web/ajax_pluginconf.php file path traversal (Exploit 130250 / EDB-35996)
1 year 3 months ago
A vulnerability classified as problematic has been found in magmi. This affects an unknown part of the file web/ajax_pluginconf.php of the component Server. The manipulation of the argument file leads to path traversal.
This vulnerability is uniquely identified as CVE-2015-2067. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
黑客利用伪造的恶意软件构建器感染了18000个“script kiddies”
1 year 3 months ago
黑客分子利用伪造的恶意软件构建器,以被称为 “script kiddies(脚本小子)” 的低技能黑客为目标,通过后门秘密感染他们,以窃取数据并接管其计算机。CloudSEK 的安全研究人员报告称,该
黑客利用伪造的恶意软件构建器感染了18000个“script kiddies”
1 year 3 months ago
他们向所有听众客户端发送了一个大规模卸载命令,遍历以前从电报日志中提取的所有已知机器ID。
Re @ben_brechtken Keiner derer, die heute leben, ist dafür verantwortlich. Man ist nur dafür verantwortlich, dass es nicht wieder passiert.
1 year 3 months ago
CVE-1999-1235 | Microsoft Internet Explorer 5.0 URL History information disclosure (EDB-19473 / XFDB-3289)
1 year 3 months ago
A vulnerability was found in Microsoft Internet Explorer 5.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component URL History Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-1999-1235. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com