Aggregator
合法跟踪定位的新思路
1 year 5 months ago
营收同比增长19.57%!一图读懂2024年第三季度报告,看国投智能All in AI
1 year 5 months ago
国投智能
梆梆安全荣获“2024年中国互联网成长型前二十家企业”
1 year 5 months ago
2024年10月17日,由中国互联网协会举办的《中国互联网企业综合实力指数(2024)》发布会在厦门成功召开, […]
梆梆安全
CVE-2018-10242 | Suricata 4.0.4 SSH Banner Parser app-layer-ssh.c out-of-bounds (DLA 1751-1 / ID 176857)
1 year 5 months ago
A vulnerability was found in Suricata 4.0.4. It has been classified as critical. This affects an unknown part of the file app-layer-ssh.c of the component SSH Banner Parser. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2018-10242. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2018-10244 | Suricata 4.0.4 EtherNet/IP PDU Parser app-layer-enip-commmon.c DecodeENIPPDU integer overflow
1 year 5 months ago
A vulnerability was found in Suricata 4.0.4. It has been rated as critical. This issue affects the function DecodeENIPPDU of the file app-layer-enip-commmon.c of the component EtherNet/IP PDU Parser. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2018-10244. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2019-18625 | Suricata 5.0.0 TCP Session TCP Timestamp injection
1 year 5 months ago
A vulnerability classified as critical has been found in Suricata 5.0.0. This affects an unknown part of the component TCP Session Handler. The manipulation as part of TCP Timestamp leads to injection.
This vulnerability is uniquely identified as CVE-2019-18625. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2019-18792 | Suricata 5.0.0 TCP Segment code injection
1 year 5 months ago
A vulnerability classified as critical was found in Suricata 5.0.0. This vulnerability affects unknown code of the component TCP Segment Handler. The manipulation leads to code injection.
This vulnerability was named CVE-2019-18792. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-44168 | Fortinet FortiOS up to 7.0.2 Restore Command range error (FG-IR-21-201)
1 year 5 months ago
A vulnerability classified as problematic was found in Fortinet FortiOS up to 7.0.2. Affected by this vulnerability is an unknown functionality of the component Restore Command Handler. The manipulation leads to range error.
This vulnerability is known as CVE-2021-44168. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-28706 | Apache Airflow Hive Provider up to 5.x code injection
1 year 5 months ago
A vulnerability was found in Apache Airflow Hive Provider up to 5.x. It has been classified as critical. This affects an unknown part. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2023-28706. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-28710 | Apache Airflow Spark Provider up to 4.0.0 input validation
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Apache Airflow Spark Provider up to 4.0.0. Affected by this issue is some unknown functionality. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2023-28710. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-27602 | Apache Linkis up to 1.3.1 PublicService Module unrestricted upload
1 year 5 months ago
A vulnerability was found in Apache Linkis up to 1.3.1. It has been declared as problematic. This vulnerability affects unknown code of the component PublicService Module. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2023-27602. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-0118 | EditTag 1.2 edittag.cgi file path traversal (EDB-29390 / BID-21890)
1 year 5 months ago
A vulnerability was found in EditTag 1.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file edittag.cgi. The manipulation of the argument file leads to path traversal.
This vulnerability is handled as CVE-2007-0118. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Grandoreiro, the global trojan with grandiose ambitions
1 year 5 months ago
Grandoreiro is a well-known Brazilian banking trojan — part of the Tetrade umbrella —
How AI Can Eliminate Graymail to Increase Employee Productivity
1 year 5 months ago
The trend toward remote working over the last several years has bred all kinds of tools intended to help us improve productivity and facilitate easier, faster digital communications with colleagues. So why does workplace productivity still feel impossible to achieve? Unfortunately, email—one of the most integral vehicles for business communication—is also one of the biggest drains on employee time and energy. According to data from Microsoft, employees spend as much as 8.8 hours each week checking and responding to email. And while many email communications are essential, one recent report found that nearly half of all emails are spam or other unwanted mail.
Check Point, Mimecast Settle SEC Case From SolarWinds Hack
1 year 5 months ago
SEC: Check Point, Mimecast Disclosures Didn't Capture Severity of SolarWinds Hack
Check Point and Mimecast will each pay regulators nearly $1 million to settle charges of making materially misleading disclosures related to the SolarWinds Orion hack. The SEC alleged public disclosures from Check Point and Mimecast didn't capture the severity of the compromise.
Check Point and Mimecast will each pay regulators nearly $1 million to settle charges of making materially misleading disclosures related to the SolarWinds Orion hack. The SEC alleged public disclosures from Check Point and Mimecast didn't capture the severity of the compromise.
Retaining EU Adequacy Crucial to UK Economy: Lawmaker
1 year 5 months ago
Europe Will Renew or Deny Data Sharing Agreement in June
The U.K. government should work ahead of a June deadline to retain its status as a trusted host of European commercial and law enforcement data, urged the head of a parliamentary committee. The economic value of an EU "adequacy agreement" is "substantial," wrote Peter Ricketts.
The U.K. government should work ahead of a June deadline to retain its status as a trusted host of European commercial and law enforcement data, urged the head of a parliamentary committee. The economic value of an EU "adequacy agreement" is "substantial," wrote Peter Ricketts.
Critical OPA Vulnerability Exposes Windows Credentials
1 year 5 months ago
Attackers Could Exploit Flaw to Relay Credentials, Compromise Systems
A critical vulnerability in Open Policy Agent could expose NTLM credentials from Windows systems, potentially affecting millions of users. Researchers at Tenable warn that attackers could exploit the flaw through social engineering. Users must update to version v0.68.0 immediately to mitigate risks.
A critical vulnerability in Open Policy Agent could expose NTLM credentials from Windows systems, potentially affecting millions of users. Researchers at Tenable warn that attackers could exploit the flaw through social engineering. Users must update to version v0.68.0 immediately to mitigate risks.
Exploring the Latest Security Innovations at Hardwear.io
1 year 5 months ago
Annual Conference and Hackathon Showcases Solutions for Protecting IoT Devices
Showcasing the latest innovations in hardware security, experts from more than 100 companies worldwide have gathered this week at Hardwear.io in Amsterdam. The annual event and hardware hackathon examines current and future challenges and solutions in hardware security.
Showcasing the latest innovations in hardware security, experts from more than 100 companies worldwide have gathered this week at Hardwear.io in Amsterdam. The annual event and hardware hackathon examines current and future challenges and solutions in hardware security.
野蛮fuzz:梦开始的地方
1 year 5 months ago
在过去的几个月里,我一直在被动地吸收大量与模糊测试相关的材料,因为我主要尝试将我的 Windows 利用技能从菜鸟级别提升到略微高级的水平,我发现它非常有趣。在这篇文章中,我将向你展示如何创建一个非常