Aggregator
CVE-2007-2658 | ID Automation Linear Barcode 1.6.0.5 ActiveX Control idautomationlinear6.dll denial of service (EDB-3917 / XFDB-34263)
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in ID Automation Linear Barcode 1.6.0.5. This issue affects some unknown processing in the library idautomationlinear6.dll of the component ActiveX Control. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2007-2658. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
城市漫步指南:关西的夏日重现
1 year 6 months ago
島のどこにても、潮の音が聞こえる。その音を追えば、会える気がした。不管在岛的哪里,都能听见潮水的声音。感觉跟着这个声音,就能遇见她。——《夏日重现》夏日就要去海边啊。今年夏天去日本是我们一早就决定的。
CVE-2007-2667 | Db Soft Lab Vimp X 4.7.3 ActiveX Control vimpx.ocx LogFile memory corruption (EDB-3916 / XFDB-34260)
1 year 6 months ago
A vulnerability classified as very critical was found in Db Soft Lab Vimp X 4.7.3. Affected by this vulnerability is an unknown functionality of the file vimpx.ocx of the component ActiveX Control. The manipulation of the argument LogFile leads to memory corruption.
This vulnerability is known as CVE-2007-2667. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
AlpacaHack Round 3 (Crypto)
1 year 6 months ago
Name: AlpacaHack Round 3 (Crypto) (an AlpacaHack event.)
Date: Sept. 15, 2024, 3 a.m. — 15 Sept. 2024, 09:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://alpacahack.com/ctfs/round-3
Rating weight: 0
Event organizers: AlpacaHack
Date: Sept. 15, 2024, 3 a.m. — 15 Sept. 2024, 09:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://alpacahack.com/ctfs/round-3
Rating weight: 0
Event organizers: AlpacaHack
赏金15000美元的 RCE
1 year 6 months ago
黑客自 8 月以来频繁利用公开漏洞攻击 WhatsUp Gold
1 year 6 months ago
胡金鱼
CVE-2014-6760 | Harem Thief Dating 1.2.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Harem Thief Dating 1.2.1. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-6760. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
大模型的幻觉是不可避免地
1 year 6 months ago
随着大模型的日益普及,批判性地检查其固有的局限性也日益重要。幻觉是大模型最常见的问题之一,我们是否可能通过改进大模型去减少或阻止幻觉的产生?United We Care 的三名研究人员在预
CVE-2014-6759 | Downton Abbey Fan Portal 1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in Downton Abbey Fan Portal 1. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-6759. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-8869 | TOTOLINK A720R 4.1.5 exportOvpn os command injection
1 year 6 months ago
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-8869. It is possible to launch the attack remotely. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2016-9878 | Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Operations / Maintenance path traversal (Nessus ID 96220 / ID 276356)
1 year 6 months ago
A vulnerability has been found in Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Operations / Maintenance. The manipulation leads to path traversal.
This vulnerability is known as CVE-2016-9878. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 11
1 year 6 months ago
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Mythical Beasts and Where to Find Them: Mapping the Global Spyware Market and its Threats to National Security and Human Rights Dissecting Lumma Malware: Analyzing the Fake CAPTCHA and Obfuscation Techniques – Part 2 Predator Spyware […]
Pierluigi Paganini
CVE-2021-31755 | Tenda AC11 up to 02.03.01.104_CN POST Request /goform/setmac stack-based overflow
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Tenda AC11 up to 02.03.01.104_CN. Affected is an unknown function of the file /goform/setmac of the component POST Request Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2021-31755. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-31207 | Microsoft Exchange Server 2013 CU23/2016 CU19/2016 CU20/2019 CU8/2019 CU9 ProxyShell unrestricted upload
1 year 6 months ago
A vulnerability classified as critical has been found in Microsoft Exchange Server 2013 CU23/2016 CU19/2016 CU20/2019 CU8/2019 CU9. Affected is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2021-31207. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-31956 | Microsoft Windows up to Server 2019 NTFS integer underflow
1 year 6 months ago
A vulnerability was found in Microsoft Windows and classified as very critical. This issue affects some unknown processing of the component NTFS. The manipulation leads to integer underflow.
The identification of this vulnerability is CVE-2021-31956. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-35211 | SolarWinds Serv-U Managed File Transfer up to 15.2.3 HF1 on Windows buffer overflow
1 year 6 months ago
A vulnerability was found in SolarWinds Serv-U Managed File Transfer up to 15.2.3 HF1 on Windows and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2021-35211. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-6758 | Mgsasia Qin Story 1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability classified as critical was found in Mgsasia Qin Story 1. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-6758. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2002-1426 | HP ProCurve Switch 4000M C.07.23 SNMP Service memory corruption (EDB-21657 / XFDB-9708)
1 year 6 months ago
A vulnerability was found in HP ProCurve Switch 4000M C.07.23. It has been rated as very critical. Affected by this issue is some unknown functionality of the component SNMP Service. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2002-1426. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
哈勃发现一对超大质量黑洞
1 year 6 months ago
当星系发生碰撞与合并时,位于其中心的超大质量黑洞也最终会合并为一个更大的黑洞。几乎每个星系的中心都拥有一个超大质量黑洞。最近哈勃太空望远镜与钱德勒 X 射线天文台在一对正在合并的星系中心发现了一对相互环绕的超大质量黑洞。这两个黑洞相距约 300 光年,预计约在 1 亿年后合并。这是迄今为止在可见光与 X 射线波段中观测到的最近距离的双超大质量黑洞。它们位于编号为 MCG-03-34-64 的星系对中心,距地球约 8 亿光年。由于黑洞吸收了周围大量的气体及尘埃,吸积作用使得该星系核心亮度大增,成为活跃星系核(AGN)。虽然过去已发现数十对双黑洞,但它们之间的距离比这次发现的要远得多。