Aggregator
HPE security advisory (AV25-058)
1 year 5 months ago
Canadian Centre for Cyber Security
CVE-2025-0675 | Elber Communications Equipment Device Configuration backdoor (icsa-25-035-03)
1 year 5 months ago
A vulnerability was found in Elber Communications Equipment and classified as critical. Affected by this issue is some unknown functionality of the component Device Configuration Handler. The manipulation leads to backdoor.
This vulnerability is handled as CVE-2025-0675. The attack may be launched remotely. There is no exploit available.
It is recommended to replace the affected component with an alternative.
vuldb.com
CVE-2025-0674 | Elber Communications Equipment authentication bypass (icsa-25-035-03)
1 year 5 months ago
A vulnerability has been found in Elber Communications Equipment and classified as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is known as CVE-2025-0674. The attack can be launched remotely. There is no exploit available.
It is recommended to replace the affected component with an alternative.
vuldb.com
U.S. CISA adds Linux kernel flaw to its Known Exploited Vulnerabilities catalog
1 year 5 months ago
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux kernel vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Linux kernel vulnerability, tracked as CVE-2024-53104, to its Known Exploited Vulnerabilities (KEV) catalog. The February 2025 Android security updates addressed 48 vulnerabilities, the zero-day flaw CVE-2024-53104 which is actively exploited in attacks […]
Pierluigi Paganini
Safepay
1 year 5 months ago
cohenido
CVE-2025-24805 | MobSF Mobile-Security-Framework-MobSF 4.3.0 Access Token privileges management (GHSA-79f6-p65j-3m2m)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in MobSF Mobile-Security-Framework-MobSF 4.3.0. Affected is an unknown function of the component Access Token Handler. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2025-24805. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24803 | MobSF Mobile-Security-Framework-MobSF 4.3.0 dynamic_analysis.html CFBundleIdentifier cross site scripting (GHSA-cxqq-w3x5-7ph3)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in MobSF Mobile-Security-Framework-MobSF 4.3.0. This issue affects some unknown processing of the file dynamic_analysis.html. The manipulation of the argument CFBundleIdentifier leads to cross site scripting.
The identification of this vulnerability is CVE-2025-24803. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24804 | MobSF Mobile-Security-Framework-MobSF 4.3.0 improper validation of specified type of input (GHSA-jrm8-xgf3-fwqr)
1 year 5 months ago
A vulnerability classified as problematic was found in MobSF Mobile-Security-Framework-MobSF 4.3.0. This vulnerability affects unknown code. The manipulation leads to improper validation of specified type of input.
This vulnerability was named CVE-2025-24804. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
BADBOX Botnet Infected Over 190,000 Android Devices Including LED TVs
1 year 5 months ago
A newly discovered botnet named BADBOX has been found to have infected over 190,000 Android devices, including high-end models like Yandex 4K QLED TVs. This botnet is particularly concerning due to its ability to infect devices potentially through pre-installed malware from the factory or further down the supply chain. The scale and stealth of BADBOX […]
The post BADBOX Botnet Infected Over 190,000 Android Devices Including LED TVs appeared first on Cyber Security News.
Tushar Subhra Dutta
FBI Watchdog: An OSINT Tool That Monitors Domain Seizures and DNS Record Changes in Real Time, Alerting Users to Law Enforcement Takedowns and Other DNS Modifications
1 year 5 months ago
FBI Watchdog: An OSINT Tool That Monitors Domain Seizures and DNS Record Changes in Real Time, Alerting Users to Law Enforcement Takedowns and Other DNS Modifications
Dark Web Informer - Cyber Threat Intelligence
CVE-2017-1515 | IBM Doors Web Access 9.5/9.6 Server Error information disclosure (XFDB-129825 / BID-102872)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in IBM Doors Web Access 9.5/9.6. This issue affects some unknown processing of the component Server Error Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2017-1515. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2017-1516 | IBM Doors Web Access 9.5/9.6 input validation (XFDB-129826 / BID-102867)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in IBM Doors Web Access 9.5/9.6. Affected is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2017-1516. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2017-1532 | IBM DOORS 9.5/9.6 Web UI cross site scripting (XFDB-130411 / BID-102888)
1 year 5 months ago
A vulnerability has been found in IBM DOORS 9.5/9.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2017-1532. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-1540 | IBM Doors Web Access 9.5/9.6 Web UI cross site scripting (XFDB-130808 / BID-102890)
1 year 5 months ago
A vulnerability was found in IBM Doors Web Access 9.5/9.6 and classified as problematic. Affected by this issue is some unknown functionality of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2017-1540. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-1545 | IBM Doors Web Access 9.5/9.6 credentials management (XFDB-130914 / BID-102896)
1 year 5 months ago
A vulnerability was found in IBM Doors Web Access 9.5/9.6. It has been classified as problematic. This affects an unknown part. The manipulation leads to credentials management.
This vulnerability is uniquely identified as CVE-2017-1545. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2017-1563 | IBM Doors Web Access 9.5/9.6 Web UI cross site scripting (XFDB-131763 / BID-102862)
1 year 5 months ago
A vulnerability was found in IBM Doors Web Access 9.5/9.6. It has been declared as problematic. This vulnerability affects unknown code of the component Web UI. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2017-1563. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2017-1567 | IBM Doors Web Access 9.5/9.6 Web UI cross site scripting (ID 351325 / XFDB-131769)
1 year 5 months ago
A vulnerability was found in IBM Doors Web Access 9.5/9.6. It has been rated as problematic. This issue affects some unknown processing of the component Web UI. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2017-1567. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2021-23165 | htmldoc up to 1.9.11 ps-pdf.cxx pspdf_prepare_outpages heap-based overflow (Issue 413)
1 year 5 months ago
A vulnerability was found in htmldoc up to 1.9.11. It has been declared as critical. This vulnerability affects the function pspdf_prepare_outpages of the file ps-pdf.cxx. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2021-23165. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-28085 | htmldoc 31f7804 ps-pdf.cxx pdf_write_names heap-based overflow (Issue 480 / Nessus ID 214518)
1 year 5 months ago
A vulnerability classified as problematic has been found in htmldoc 31f7804. This affects the function pdf_write_names of the file ps-pdf.cxx. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2022-28085. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com