Aggregator
CVE-2019-8660 | Apple macOS up to 10.14.5 Core Data memory corruption (HT210348 / EDB-47193)
1 year 3 months ago
A vulnerability classified as critical was found in Apple macOS up to 10.14.5. Affected by this vulnerability is an unknown functionality of the component Core Data. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2019-8660. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
秘密后门使用“魔法封包”感染企业 VPN
1 year 3 months ago
当攻击者利用后门在目标网络获得访问权限之后,他们希望其努力成果不会被竞争对手利用或被安全软件监测出。他们可使用的一种应对之策是为后门配备一个被动代理,该代理将保持休眠状态,直到接收到“魔法封包”。安全公司 Lumin Technology 的研究人员报告了 J-Magic 后门使用“魔法封包”悄悄控制了数十个运行 Juniper Network Junos OS 的企业 VPN。J-Magic 是轻量级后门程序,只运行在内存之中,这增加了其被安全软件检测出的难度。研究人员是在 VirusTotal 上发现了 J-Magic,发现它在 36 个组织的网络内运行,他们不清楚后门是如何安装的。J-Magic 从 2023 年中期至少活跃到 2024 年中期,其目标覆盖半导体、能源、制造业和 IT 垂直企业。
A Threat Actor is Selling Access to an Unidentified WordPress Store in India
1 year 3 months ago
A Threat Actor is Selling Access to an Unidentified WordPress Store in India
Dark Web Informer - Cyber Threat Intelligence
CVE-2002-1482 | phpGB 1.10/1.20/1.30 magic_quotes_gpc login.php Password sql injection (EDB-21778 / ID 10821)
1 year 3 months ago
A vulnerability was found in phpGB 1.10/1.20/1.30 and classified as critical. Affected by this issue is some unknown functionality of the file login.php of the component magic_quotes_gpc. The manipulation of the argument Password leads to sql injection.
This vulnerability is handled as CVE-2002-1482. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
How to Choose the Right Cybersecurity Software: A Comprehensive Guide
1 year 3 months ago
Navigate the complex world of cybersecurity software selection with confidence. This practical guide helps business leaders understand modern security threats, evaluate solutions, and implement effective protection strategies.
The post How to Choose the Right Cybersecurity Software: A Comprehensive Guide appeared first on Security Boulevard.
Deepak Gupta - Tech Entrepreneur, Cybersecurity Author
CVE-2010-2428 | WinFTP Wing FTP Server up to 3.2.0 admin_loginok.html cross site scripting (Nessus ID 47698 / ID 27326)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in WinFTP Wing FTP Server up to 3.2.0. This issue affects some unknown processing of the file admin_loginok.html. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2010-2428. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2010-2421 | Opera Web Browser up to 7.19 memory corruption (Nessus ID 47113 / ID 118121)
1 year 3 months ago
A vulnerability has been found in Opera Web Browser up to 7.19 and classified as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2010-2421. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-2400 | Oracle OpenSolaris Filesystem denial of service (ID 118374 / SBV-26440)
1 year 3 months ago
A vulnerability was found in Oracle OpenSolaris. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Filesystem. The manipulation leads to denial of service.
This vulnerability is known as CVE-2010-2400. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2011-1518 | OTRS up to 3.0.6 cross site scripting (dsa-2231 / Nessus ID 75702)
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in OTRS. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2011-1518. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-2435 | Salvo Tomaselli Weborf HTTP Server up to 0.12.1 Connection Header Unicode input validation (EDB-14012 / ID 118147)
1 year 3 months ago
A vulnerability was found in Salvo Tomaselli Weborf HTTP Server up to 0.12.1 and classified as problematic. Affected by this issue is some unknown functionality of the component Connection Header Handler. The manipulation as part of Unicode leads to improper input validation.
This vulnerability is handled as CVE-2010-2435. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Hacker infects 18,000 "script kiddies" with fake malware builder
1 year 3 months ago
A threat actor targeted low-skilled hackers, known as "script kiddies," with a fake malware builder that secretly infected them with a backdoor to steal data and take over computers. [...]
Bill Toulas
CVE-2006-3435 | Microsoft Office 2000/2003/2004/Xp code injection (VU#187028 / Nessus ID 22531)
1 year 3 months ago
A vulnerability was found in Microsoft Office 2000/2003/2004/Xp and classified as very critical. This issue affects some unknown processing. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2006-3435. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-2387 | Microsoft Office 2000/2001/2003/2004 memory corruption (VU#706668 / Nessus ID 22532)
1 year 3 months ago
A vulnerability was found in Microsoft Office 2000/2001/2003/2004. It has been classified as critical. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2006-2387. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-2444 | Linux Kernel up to 2.6.16.17 snmp_trap_decode denial of service (VU#681569 / EDB-1880)
1 year 3 months ago
A vulnerability was found in Linux Kernel up to 2.6.16.17. It has been declared as critical. Affected by this vulnerability is the function snmp_trap_decode. The manipulation leads to denial of service.
This vulnerability is known as CVE-2006-2444. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-0615 | Sun JRE 1.4.2/1.5.0 Java Sandbox memory corruption (VU#759996 / Nessus ID 20921)
1 year 3 months ago
A vulnerability was found in Sun JRE 1.4.2/1.5.0. It has been declared as critical. This vulnerability affects unknown code of the component Java Sandbox. The manipulation leads to memory corruption.
This vulnerability was named CVE-2006-0615. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
A Threat Actor Claims to be Selling the Data of IDNIC
1 year 3 months ago
A Threat Actor Claims to be Selling the Data of IDNIC
Dark Web Informer - Cyber Threat Intelligence
CVE-2023-31146 | Vyper up to 0.3.7 codegen out-of-bounds write (GHSA-3p37-3636-q8wv)
1 year 3 months ago
A vulnerability was found in Vyper up to 0.3.7. It has been declared as critical. This vulnerability affects unknown code of the component codegen. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2023-31146. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-32058 | Vyper up to 0.3.7 integer overflow (GHSA-6r8q-pfpv-7cgj)
1 year 3 months ago
A vulnerability was found in Vyper up to 0.3.7. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2023-32058. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-13378 | Loadbalancer.org Enterprise VA MAX up to 8.3.8 os command injection
1 year 3 months ago
A vulnerability classified as critical has been found in Loadbalancer.org Enterprise VA MAX up to 8.3.8. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2020-13378. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com