Aggregator
eBPF项目开发环境meson化之旅
1 year 4 months ago
eBPF项目开发环境meson化之旅
1 year 4 months ago
CVE-2024-52912 | Bitcoin Core up to 0.20.x Split integer overflow
1 year 4 months ago
A vulnerability, which was classified as problematic, has been found in Bitcoin Core up to 0.20.x. This issue affects some unknown processing of the component Split Handler. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2024-52912. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38828 | Vmware Spring Framework up to 5.3.41 MVC Controller denial of service
1 year 4 months ago
A vulnerability classified as problematic was found in Vmware Spring Framework up to 5.3.41. This vulnerability affects unknown code of the component MVC Controller. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-38828. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52943 | Veritas Enterprise Vault up to 15.1 HTTP Request cross site scripting (ZDI-CAN-24697)
1 year 4 months ago
A vulnerability classified as problematic has been found in Veritas Enterprise Vault up to 15.1. This affects an unknown part of the component HTTP Request Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-52943. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-52942 | Veritas Enterprise Vault up to 15.1 HTTP Request cross site scripting
1 year 4 months ago
A vulnerability was found in Veritas Enterprise Vault up to 15.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-52942. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-52941 | Veritas Enterprise Vault up to 15.1 HTTP Request cross site scripting (ZDI-CAN-24695)
1 year 4 months ago
A vulnerability was found in Veritas Enterprise Vault up to 15.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-52941. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-52944 | Veritas Enterprise Vault up to 15.1 HTTP Request cross site scripting (ZDI-CAN-24698)
1 year 4 months ago
A vulnerability was found in Veritas Enterprise Vault up to 15.1. It has been classified as problematic. Affected is an unknown function of the component HTTP Request Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-52944. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-52946 | LemonLDAP::NG up to 2.20.0 Session Refresh improper authentication (Issue 3255)
1 year 4 months ago
A vulnerability was found in LemonLDAP::NG up to 2.20.0 and classified as critical. This issue affects some unknown processing of the component Session Refresh. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2024-52946. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
What Is The Content Delivery & Security Association (CDSA)?
1 year 4 months ago
The Content Delivery & Security Association (CDSA) has long been a cornerstone in the media and entertainment industries. It ensures that the highest content security and delivery standards are met. As the digital landscape continues to evolve, the role of the CDSA has become more critical than ever. It addresses new challenges and provides innovative […]
The post What Is The Content Delivery & Security Association (CDSA)? appeared first on Centraleyes.
The post What Is The Content Delivery & Security Association (CDSA)? appeared first on Security Boulevard.
Rebecca Kappel
CVE-2024-52945 | Veritas NetBackup up to 10.4 on Windows untrusted search path
1 year 4 months ago
A vulnerability has been found in Veritas NetBackup up to 10.4 on Windows and classified as critical. This vulnerability affects unknown code. The manipulation leads to untrusted search path.
This vulnerability was named CVE-2024-52945. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52926 | Delinea Privilege Manager up to 12.0.1 Agent Local Privilege Escalation
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Delinea Privilege Manager up to 12.0.1. This affects an unknown part of the component Agent. The manipulation leads to Local Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-52926. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43704 | Imagination Technologies Graphics DDK up to 24.2 RTM1 GPU System Call exposure of resource
1 year 4 months ago
A vulnerability, which was classified as problematic, has been found in Imagination Technologies Graphics DDK up to 24.2 RTM1. Affected by this issue is some unknown functionality of the component GPU System Call Handler. The manipulation leads to exposure of resource.
This vulnerability is handled as CVE-2024-43704. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52920 | Bitcoin Core up to 0.19.x GETDATA Message denial of service
1 year 4 months ago
A vulnerability classified as problematic was found in Bitcoin Core up to 0.19.x. Affected by this vulnerability is an unknown functionality of the component GETDATA Message Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-52920. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52915 | Bitcoin Core up to 0.19.x INV Message memory allocation
1 year 4 months ago
A vulnerability classified as problematic has been found in Bitcoin Core up to 0.19.x. Affected is an unknown function of the component INV Message Handler. The manipulation leads to uncontrolled memory allocation.
This vulnerability is traded as CVE-2024-52915. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52922 | Bitcoin Core up to 25.0 Block denial of service
1 year 4 months ago
A vulnerability was found in Bitcoin Core up to 25.0. It has been rated as problematic. This issue affects some unknown processing of the component Block Handler. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2024-52922. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52917 | Bitcoin Core up to 21.x on MiniUPnP infinite loop
1 year 4 months ago
A vulnerability was found in Bitcoin Core up to 21.x on MiniUPnP. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to infinite loop.
This vulnerability was named CVE-2024-52917. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52940 | AnyDesk up to 8.1.0 on Windows Allow Direct Connection information disclosure
1 year 4 months ago
A vulnerability was found in AnyDesk up to 8.1.0 on Windows. It has been classified as problematic. This affects an unknown part of the component Allow Direct Connection Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-52940. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Analyzing JtR's Tokenizer Attack (Round 1)
1 year 4 months ago
This is a follow-up to my previous blog post looking at how to install/run the new John the Ripper