Aggregator
《攻击面管理技术应用指南(2024版)》报告发布(附下载二维码)
1 year 3 months ago
随着云计算、物联网和移动互联网等技术的普及,企业传统的安全边界正不断被打破,攻击面以惊人的速度扩张,导致安全威 […]
aqniu
外交部、商务部就美国政府可能针对TP-Link的禁令同时发声;苹果公司点名Meta,质疑欧盟数据互操作要求暗藏隐私风险 | 牛览
1 year 3 months ago
新闻速览 •外交部、商务部就美国政府可能针对TP-Link的禁令同时发声 •网信部门从严打击网上侵害未成年人合 […]
aqniu
斗象科技×某省级运营商: XSOC一体化综合指挥运营平台「创新实践」
1 year 3 months ago
复杂形势下,运营商在安全管理上面临管理缺乏整体性、技术缺乏系统性、处置缺乏有效性等困境,在内生管理基因以及外在各类需求的双重驱动下,运营商势必要走向常态化、实战化、集约化、智能化的一体化网络与信息安全
斗象科技×某省级运营商: XSOC一体化综合指挥运营平台「创新实践」
1 year 3 months ago
Why cybersecurity is critical to energy modernization
1 year 3 months ago
In this Help Net Security interview, Anjos Nijk, Managing Director of the European Network for Cyber security (ENCS), discusses cybersecurity in the energy sector as it modernizes with renewable sources and smart grid technologies. Nijk also addresses the need for international collaboration, the impact of IoT on security, and the emerging technologies that can enhance the resilience and reliability of critical energy infrastructure. As the energy sector undergoes significant modernization, particularly with the integration of … More →
The post Why cybersecurity is critical to energy modernization appeared first on Help Net Security.
Mirko Zorz
CVE-2014-1419 | Canonical acpi-support 0.141 Privileges race condition (USN-2297-1 / Nessus ID 76707)
1 year 3 months ago
A vulnerability classified as critical has been found in Canonical acpi-support 0.141. Affected is an unknown function of the component Privileges. The manipulation leads to race condition.
This vulnerability is traded as CVE-2014-1419. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-1424 | AppArmor 2.8.94-0ubuntu1.4 access control (USN-2413-1 / Nessus ID 79383)
1 year 3 months ago
A vulnerability was found in AppArmor 2.8.94-0ubuntu1.4. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2014-1424. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-1421 | Cononical Ubuntu 14.10 Access Restriction access control (USN-2411-1 / Nessus ID 79333)
1 year 3 months ago
A vulnerability has been found in Cononical Ubuntu 14.10 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Access Restriction. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2014-1421. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2014-1425 | Linuxcontainers Cgmanager 0.32 access control (USN-2451-1 / Nessus ID 80392)
1 year 3 months ago
A vulnerability classified as problematic has been found in Linuxcontainers Cgmanager 0.32. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2014-1425. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2014-1459 | doorGets CMS 3.0/4.0/5.2 _position_down_id sql injection (Advisory 125078 / EDB-31521)
1 year 3 months ago
A vulnerability was found in doorGets CMS 3.0/4.0/5.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument _position_down_id leads to sql injection.
The identification of this vulnerability is CVE-2014-1459. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-1517 | Mozilla Bugzilla 4.0/4.2/4.4rc1 Data Display improper authentication (Bug 968576 / Nessus ID 73632)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Mozilla Bugzilla 4.0/4.2/4.4rc1. Affected by this issue is some unknown functionality of the component Data Display Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2014-1517. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-1610 | MediaWiki up to 1.22.1 pdfhandler_body.php input validation (EDB-31329 / Nessus ID 72618)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in MediaWiki. Affected is an unknown function of the file pdfhandler_body.php. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2014-1610. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
外交部、商务部就美国政府可能针对TP-Link的禁令同时发声;苹果公司点名Meta,质疑欧盟数据互操作要求暗藏隐私风险 | 牛览
1 year 3 months ago
新闻速览•外交部、商务部就美国政府可能针对TP-Link的禁令同时发声•网信部门从严打击网上侵害未成年人合法权益行为•《网络安全标准实践指南—— 一键停止收集车外数据指引》发布•国际刑警组织呼吁用“情
《攻击面管理技术应用指南(2024版)》报告发布(附下载二维码)
1 year 3 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2014-1671 | Dell Kace K1000 Systems Management Appliance Software 5.4.76847 ORDER[] sql injection (EDB-27039 / Nessus ID 72392)
1 year 3 months ago
A vulnerability was found in Dell Kace K1000 Systems Management Appliance Software 5.4.76847. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument ORDER[] leads to sql injection.
This vulnerability is known as CVE-2014-1671. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-1610 | MediaWiki up to 1.22.1 thumb.php page input validation (EDB-31329 / Nessus ID 72618)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in MediaWiki. This issue affects some unknown processing of the file thumb.php. The manipulation of the argument page leads to improper input validation.
The identification of this vulnerability is CVE-2014-1610. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-1680 | Bandisoft Bandizip up to 3.09 dwmapi.dll untrusted search path (ID 125059 / ID 122633)
1 year 3 months ago
A vulnerability was found in Bandisoft Bandizip up to 3.09 and classified as critical. This issue affects some unknown processing in the library dwmapi.dll. The manipulation leads to untrusted search path.
The identification of this vulnerability is CVE-2014-1680. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-1691 | Horde Groupware up to 5.1.0 Util Library variables.php _formvars code injection (Nessus ID 72353 / ID 175269)
1 year 3 months ago
A vulnerability classified as critical has been found in Horde Groupware up to 5.1.0. Affected is an unknown function in the library framework/util/lib/horde/variables.php of the component Util Library. The manipulation of the argument _formvars leads to code injection.
This vulnerability is traded as CVE-2014-1691. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-1684 | VideoLAN VLC Media Player up to 2.1.2 ASF File numeric error (EDB-31429 / Nessus ID 89901)
1 year 3 months ago
A vulnerability was found in VideoLAN VLC Media Player up to 2.1.2. It has been classified as problematic. Affected is an unknown function of the component ASF File Handler. The manipulation leads to numeric error.
This vulnerability is traded as CVE-2014-1684. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com