Aggregator
火绒安全终端防护数据月报(2024-12)
1 year 3 months ago
12月,火绒安全产品拦截恶意攻击总数185,909,512次,其中病毒拦截1.1亿次、系统高危动作拦截4006.8万次、网络高危风险拦截3993.3万次。
CVE-2023-36268 | Document Foundation LibreOffice 7.4.7 PPT File denial of service
1 year 3 months ago
A vulnerability was found in Document Foundation LibreOffice 7.4.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the component PPT File Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2023-36268. The attack may be launched remotely. There is no exploit available.
vuldb.com
Some weeks in security (December 16 – January 5)
1 year 3 months ago
绿盟虚拟汽车的CAN总线攻防实战
1 year 3 months ago
前期,我们已经撰写《绿盟虚拟汽车靶场及其优势》一文,以阐述绿盟虚拟汽车靶场的优势与攻防实战表现,表明虚拟汽车在虚拟电子电气架构的虚拟化方面表现出色。本文作为补充,基于CAN总线攻防实战,进一步阐述绿盟虚拟汽车在CAN总线攻防方面的表现
绿盟虚拟汽车的CAN总线攻防实战
1 year 3 months ago
一. 背景绿盟突破技术壁垒,使得虚拟汽车零部件具备嵌入式操作系统(嵌入式Linux、嵌入式Android),多个虚拟零部件可以加入虚拟汽车CAN网络中相互进行CAN总线通信,构建出完整的汽车电子电气
CVE-2023-45916 | Freedesktop Xedit 1.2.3 LSP File /X11/xedit/lisp null pointer dereference
1 year 3 months ago
A vulnerability was suspected in Freedesktop Xedit 1.2.3. Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2023-42915 | Apple macOS curl Privilege Escalation
1 year 3 months ago
A vulnerability was suspected in Apple macOS. This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2023-42915 | Apple iOS/iPadOS curl Privilege Escalation
1 year 3 months ago
A vulnerability was suspected in Apple iOS and iPadOS. This issue appears to be a false-positive. Please verify the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2023-41696 | User Submitted Posts Plugin up to 20230901 on WordPress Shortcode cross site scripting
1 year 3 months ago
A vulnerability was suspected in User Submitted Posts Plugin up to 20230901. Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2023-40533 | Tinyproxy 1.11.1 HTTP Request uninitialized variable (TALOS-2023-1902)
1 year 3 months ago
A vulnerability was suspected in Tinyproxy 1.11.1. This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2023-37621 | Fronius Datalogger Web 2.0.5-4 Request information disclosure (CNVD-2022-2736)
1 year 3 months ago
A vulnerability was suspected in Fronius Datalogger Web 2.0.5-4. Further analysis revealed that this issues is a false-positive. Please take a look at the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2023-20239 | Cisco FirePOWER Management Center sql injection (cisco-sa-fmc-sqli-WFFDnNOs)
1 year 3 months ago
A vulnerability was suspected in Cisco FirePOWER Management Center. This issue appears to be a false-positive. Please verify the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2022-29409 | ThingsForRestaurants Quick Restaurant Reservations Plugin up to 1.4.1 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was suspected in ThingsForRestaurants Quick Restaurant Reservations Plugin up to 1.4.1. Further analysis revealed that this issues is a false-positive. Please take a look at the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2021-47285 | Linux Kernel up to 5.12.10 net/nfc/rawsock.c rawsock_create permission
1 year 3 months ago
A vulnerability was suspected in Linux Kernel up to 5.12.10. Further analysis revealed that this issues is a false-positive. Please take a look at the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2021-47487 | Linux Kernel up to 5.10.76/5.14.15 amdgpu wr_buf out-of-bounds write (eb3b6805e3e9/d3ed72495a59/5afa7898ab7a)
1 year 3 months ago
A vulnerability was suspected in Linux Kernel up to 5.10.76/5.14.15. This issue appears to be a false-positive. Please verify the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2021-47326 | Linux Kernel up to 5.4.133/5.10.51/5.12.18/5.13.3 on_sig_stack stack-based overflow
1 year 3 months ago
A vulnerability was suspected in Linux Kernel up to 5.4.133/5.10.51/5.12.18/5.13.3. This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all.
vuldb.com
Top 100 Highest Paying Upwork Clients
1 year 3 months ago
Hope you enjoyed the holidays, my fellow freelancers!Here’s how we’re gonna do it. First, go through
男子被困在在一直绕圈的 Waymo 无人驾驶出租车中
1 year 3 months ago
Michael Johns 乘坐 Waymo 的无人驾驶出租车前往机场,但这辆汽车却在停车场不停绕圈子,而行驶过程中他无法打开车门离开。被困车中期间,他打电话给 Waymo 寻求帮助,担心汽车是不是被黑客入侵。他拍下了整个过程,将其发布在职业社交网络 linkedin 上。数分钟后,Waymo 的工程师终于控制了汽车,让他能及时赶到机场搭上前往洛杉矶的航班。他认为这起事件是今天数字世界的一种典型,一种尚不成熟的产品。他表示以后不打算再搭乘 Waymo 的汽车。而 Waymo 对此回应称,这次事故增加了 5 分钟的行程时间,他们没有向 Johns 收取车费,而软件故障已经解决。
男子被困在在一直绕圈的 Waymo 无人驾驶出租车中
1 year 3 months ago
Michael Johns 乘坐 Waymo 的无人驾驶出租车前往机场,但这辆汽车却在停车场不停绕圈子,而行驶过程中他无法打开车门离开。被困车中期间,他打电话给 Waymo 寻求帮助,担心