Aggregator
CVE-2016-5180 | c-ares up to 1.11.x ares_create_query out-of-bounds write (FEDORA-2016-4f34f26649 / Nessus ID 94805)
1 year 6 months ago
A vulnerability, which was classified as very critical, has been found in c-ares up to 1.11.x. This issue affects the function ares_create_query. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2016-5180. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
宫本茂称任天堂在采用 AI 上会走不同的方向
1 year 6 months ago
游戏公司纷纷拥抱生成式 AI,但任天堂的传奇设计师宫本茂表示,该公司会走不同的方向。宫本茂表示这不是为了走反方向而走反方向,这是为了尝试找出任天堂的特别之处。有很多关于 AI 的讨论。每个人都朝着相同的方向前进,但任天堂宁愿走不同的方向。任天堂总裁古川俊太郎在 7 月回答投资者提问时也对 AI 的使用表达了模糊的立场,称生成式 AI 可以创造性的使用,但也可能引发知识产权方面的问题。
CVE-2024-46834 | Linux Kernel up to 6.10.9 ethtool out-of-bounds (101737d8b88d/2899d58462ba)
1 year 6 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.10.9. This issue affects some unknown processing of the component ethtool. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-46834. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
«Рации на палке»: как Чикаго потратил состояние на бесполезную технологию отслеживания
1 year 6 months ago
Дорогостоящая система привела к произволу полиции и дискриминации населения.
CVE-2024-46820 | Linux Kernel up to 6.10.8 AMD Display amdgpu_irq_put state issue (aa92264ba6fd/10fe1a79cd1b)
1 year 6 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.10.8. This vulnerability affects the function amdgpu_irq_put of the component AMD Display. The manipulation leads to state issue.
This vulnerability was named CVE-2024-46820. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46818 | Linux Kernel up to 6.10.8 AMD Display gpio_id array index
1 year 6 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.10.8. This affects the function gpio_id of the component AMD Display. The manipulation leads to improper validation of array index.
This vulnerability is uniquely identified as CVE-2024-46818. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46817 | Linux Kernel up to 6.10.8 AMD Display amdgpu_dm initialization
1 year 6 months ago
A vulnerability was found in Linux Kernel up to 6.10.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component AMD Display. The manipulation of the argument amdgpu_dm leads to improper initialization.
This vulnerability is handled as CVE-2024-46817. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CUPS flaws allow remote code execution on Linux systems under certain conditions
1 year 6 months ago
A researcher has disclosed details of an unpatched Linux vulnerability, initially labeled as critical, that allows remote code execution. The popular cybersecurity researcher Simone Margaritelli (@evilsocket) disclosed technical details of an unpatched vulnerability impacting Linux systems. On September 23, Margaritelli announced plans to disclose an unauthenticated remote code execution (RCE) vulnerability affecting all GNU/Linux systems […]
Pierluigi Paganini
CVE-2024-46816 | Linux Kernel up to 6.10.8 AMD Display amdgpu_dm initialization (36c39a8dcce2/cf8b16857db7)
1 year 6 months ago
A vulnerability was found in Linux Kernel up to 6.10.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component AMD Display. The manipulation of the argument amdgpu_dm leads to improper initialization.
This vulnerability is known as CVE-2024-46816. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46815 | Linux Kernel up to 6.10.8 AMD Display num_valid_sets information disclosure
1 year 6 months ago
A vulnerability was found in Linux Kernel up to 6.10.8. It has been classified as problematic. Affected is the function num_valid_sets of the component AMD Display. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-46815. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46814 | Linux Kernel up to 5.10.225/5.15.166/6.1.108/6.6.49/6.10.8 AMD Display msg_id array index
1 year 6 months ago
A vulnerability was found in Linux Kernel up to 5.10.225/5.15.166/6.1.108/6.6.49/6.10.8 and classified as critical. This issue affects some unknown processing of the component AMD Display. The manipulation of the argument msg_id leads to improper validation of array index.
The identification of this vulnerability is CVE-2024-46814. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
H7CTF International
1 year 6 months ago
Name: H7CTF International (an H7CTF International event.)
Date: Sept. 26, 2024, 3:30 a.m. — 27 Sept. 2024, 11:30 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.h7tex.com/
Rating weight: 22.67
Event organizers: H7Tex
Date: Sept. 26, 2024, 3:30 a.m. — 27 Sept. 2024, 11:30 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.h7tex.com/
Rating weight: 22.67
Event organizers: H7Tex
Memory-Safe Coding Cuts Android System Flaws by 75%
1 year 6 months ago
Google Says Rust Language Initiative Eliminates Cross-Site Scripting, Other Flaws
Google says switching to a memory-safe language such as Rust under its Safe Coding program has helped significantly reduce the number of vulnerabilities in Android systems. The number of vulnerabilities uncovered in Android devices has fallen from over 200 in 2019 to fewer than 50 by 2024.
Google says switching to a memory-safe language such as Rust under its Safe Coding program has helped significantly reduce the number of vulnerabilities in Android systems. The number of vulnerabilities uncovered in Android devices has fallen from over 200 in 2019 to fewer than 50 by 2024.
Breach Roundup: How to Spot North Korean IT Workers
1 year 6 months ago
Also: Ransomware Surged in 2023, MoneyGram Back in Service After Cyberattack
This week, advice on spotting North Korean staff; ransomware attacks rose; MoneyGram back online; FCC fined political operative; CISA warned of water system attacks; Ukraine restricted Telegram use; North Korean hackers used new malware; U.K. arrested alleged hacker; PSNI is in data leak talks.
This week, advice on spotting North Korean staff; ransomware attacks rose; MoneyGram back online; FCC fined political operative; CISA warned of water system attacks; Ukraine restricted Telegram use; North Korean hackers used new malware; U.K. arrested alleged hacker; PSNI is in data leak talks.
NIST Calls for Major Overhaul in Typical Password Practices
1 year 6 months ago
Draft Guidelines Call for Longer, Randomized Passwords Instead of Memorized Phrases
The National Institute of Standards and Technology is calling for longer, randomized passwords instead of memorized phrases containing combinations of upper and lowercase letters in new guidance that aims to modernize current password practices across the public and private sectors.
The National Institute of Standards and Technology is calling for longer, randomized passwords instead of memorized phrases containing combinations of upper and lowercase letters in new guidance that aims to modernize current password practices across the public and private sectors.
Visa Acquires AI Leader Featurespace for Payments Protection
1 year 6 months ago
Featurespace's AI Expertise Will Enhance Visa's Fraud, Risk and Payments Technology
Visa has signed a definitive agreement to acquire AI-driven fraud prevention leader Featurespace. This acquisition will reinforce Visa's fraud detection capabilities, integrating advanced machine learning technology to strengthen financial crime prevention and protect global transactions.
Visa has signed a definitive agreement to acquire AI-driven fraud prevention leader Featurespace. This acquisition will reinforce Visa's fraud detection capabilities, integrating advanced machine learning technology to strengthen financial crime prevention and protect global transactions.
Could Security Misconfigurations Become No. 1 in OWASP Top 10?
1 year 6 months ago
As Superman has kryptonite, software has weaknesses — with misconfigurations leading the pack.
Mark Troester
CVE-2024-46812 | Linux Kernel up to 6.1.108/6.6.49/6.10.8 AMD Display Privilege Escalation
1 year 6 months ago
A vulnerability has been found in Linux Kernel up to 6.1.108/6.6.49/6.10.8 and classified as problematic. This vulnerability affects unknown code of the component AMD Display. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2024-46812. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46829 | Linux Kernel up to 6.10.9 rt_mutex_handle_deadlock
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.10.9. This affects the function rt_mutex_handle_deadlock. The manipulation leads to deadlock.
This vulnerability is uniquely identified as CVE-2024-46829. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com