Aggregator
.NET | 详解通过Win32函数实现本地提权
1 year 3 months ago
CVE-2012-1165 | OpenSSL up to 0.9.8u/1.0.0h crypto/asn1/asn_mime.c mime_param_cmp resource management (Nessus ID 74590 / ID 185004)
1 year 3 months ago
A vulnerability was found in OpenSSL up to 0.9.8u/1.0.0h. It has been declared as critical. This vulnerability affects the function mime_param_cmp of the file crypto/asn1/asn_mime.c. The manipulation leads to improper resource management.
This vulnerability was named CVE-2012-1165. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-1795 | webglimpse up to 2.17.1 webglimpse.cgi query os command injection (VU#364363 / Nessus ID 58412)
1 year 3 months ago
A vulnerability was found in webglimpse up to 2.17.1. It has been declared as critical. This vulnerability affects unknown code of the file webglimpse.cgi. The manipulation of the argument query leads to os command injection.
This vulnerability was named CVE-2012-1795. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-1762 | Opera Web Browser up to 7.19 resource management (EDB-31594 / Nessus ID 31831)
1 year 3 months ago
A vulnerability has been found in Opera Web Browser up to 7.19 and classified as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2008-1762. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
派早报:EA 发布 2024 年玩家游玩报告、上海市通报侵害用户权益行为 App 等
1 year 3 months ago
Behind the Scenes: Understanding CVE-2022-24547
1 year 3 months ago
Vulnerabilities can often be found in places we don’t expect, and CVE-2022-24547 in CastSrv.exe is
活动预告|CodeWisdom 软件智能化开发学术系列报告 第14期:重新定义团队协作-面向下一代软件工程的LLM Agents
1 year 3 months ago
Tse-Hsun (Peter) ChenLeader of the Software PErformance, Analysis, and Reliability (SPEAR) lab at Co
All I Want for Christmas is a CVE-2024-30085 Exploit
1 year 3 months ago
CVE-2024-30085 is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini
The Top 10 Data Breaches of 2024
1 year 3 months ago
2024 has been a tumultuous year in cybersecurity with numerous significant data breaches compromisin
活动预告|CodeWisdom 软件智能化开发学术系列报告 第14期:重新定义团队协作-面向下一代软件工程的LLM Agents
1 year 3 months ago
报告时间:2024年12月26日(周四)上午10:00
威努特为医疗物联网筑造安全防护矩阵
1 year 3 months ago
守护智慧医疗安全底线!
威努特为医疗物联网筑造安全防护矩阵
1 year 3 months ago
01IoMT背景介绍医疗物联网(IoMT:Internet of Medical Things)是物联网在医疗行业的重要应用。随着医疗行业大力推进数字化和智能化转型,IoMT技术已经成为提升医疗服务效
Daily Dose of Dark Web Informer - December 23rd, 2024
1 year 3 months ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2018-25106 | webuidesigning NebulaX Theme up to 5.0 on WordPress libs/Legacy/Legacy.php nebula_send_to_hubspot sql injection
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2018-25106. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
A Threat Actor Claims to be Selling the Data of Cashory
1 year 3 months ago
A Threat Actor Claims to be Selling the Data of Cashory
Dark Web Informer - Cyber Threat Intelligence
CVE-2002-1451 | Desiderata Software Blazix 1.2/1.2.1 HTTP Request Source information disclosure (EDB-21752 / Nessus ID 17151)
1 year 3 months ago
A vulnerability classified as critical was found in Desiderata Software Blazix 1.2/1.2.1. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to information disclosure (Source).
This vulnerability was named CVE-2002-1451. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-1727 | Mozilla Firefox up to 23.0.1 file:/ cross site scripting (EDB-38766 / Nessus ID 70036)
1 year 3 months ago
A vulnerability was found in Mozilla Firefox up to 23.0.1. It has been declared as problematic. This vulnerability affects unknown code of the component file:/ Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2013-1727. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-8636 | Mozilla Firefox 34.0.5 XrayWrapper DOM Object code injection (MFSA2015-09 / EDB-36480)
1 year 3 months ago
A vulnerability was found in Mozilla Firefox 34.0.5. It has been rated as problematic. Affected by this issue is some unknown functionality of the component XrayWrapper. The manipulation as part of DOM Object leads to code injection.
This vulnerability is handled as CVE-2014-8636. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-44655 | Online Pre-owned Showroom Management System 1.0 Login Form sql injection (Exploit 50560 / EDB-50560)
1 year 3 months ago
A vulnerability was found in Online Pre-owned Showroom Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component Login Form. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2021-44655. Access to the local network is required for this attack. Furthermore, there is an exploit available.
vuldb.com