Aggregator
CVE-2017-0042 | Microsoft Windows Vista SP2 up to Server 2016 DirectShow information disclosure (MS17-021 / Nessus ID 97736)
1 year 6 months ago
A vulnerability, which was classified as problematic, was found in Microsoft Windows. Affected is an unknown function of the component DirectShow. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2017-0042. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
仅剩6天 | WitAwards 2024网安年度评选报名从速!
1 year 6 months ago
主站 分类 漏洞 工具 极客
CVE-2024-4660 | GitLab Enterprise Edition up to 17.1.6/17.2.4/17.3.1 Private Project authorization (Issue 460892)
1 year 6 months ago
A vulnerability was found in GitLab Enterprise Edition up to 17.1.6/17.2.4/17.3.1. It has been rated as problematic. This issue affects some unknown processing of the component Private Project Handler. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-4660. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6389 | GitLab Community Edition/Enterprise Edition up to 17.1.6/17.2.4/17.3.1 Atom Endpoint exposure of sensitive system information to an unauthorized control sphere (Issue 469367)
1 year 6 months ago
A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition up to 17.1.6/17.2.4/17.3.1. Affected is an unknown function of the component Atom Endpoint. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is traded as CVE-2024-6389. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-25270 | Mirapolis LMS 4.6.x ID/STEP resource injection
1 year 6 months ago
A vulnerability classified as problematic has been found in Mirapolis LMS 4.6.x. Affected is an unknown function. The manipulation of the argument ID/STEP leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2024-25270. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-46691 | Linux Kernel up to 6.10.7 ucsi_unregister null pointer dereference (095b0001aefd/11bb2ffb6793)
1 year 6 months ago
A vulnerability was found in Linux Kernel up to 6.10.7. It has been declared as critical. Affected by this vulnerability is the function ucsi_unregister. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-46691. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46682 | Linux Kernel up to 6.10.7 states states_show sc_type state issue (ba0b697de298/a204501e1743)
1 year 6 months ago
A vulnerability has been found in Linux Kernel up to 6.10.7 and classified as problematic. Affected by this vulnerability is the function states_show of the file /proc/fs/nfsd/clients/2/states. The manipulation of the argument sc_type leads to state issue.
This vulnerability is known as CVE-2024-46682. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
苹果宣布自9月16日开始欧盟版iPadOS将支持第三方提供的替代商店
1 year 6 months ago
CVE-2007-2599 | TutorialCMS browseSubCat.php catFile sql injection (EDB-3887 / XFDB-34214)
1 year 6 months ago
A vulnerability classified as critical has been found in TutorialCMS. This affects an unknown part of the file browseSubCat.php. The manipulation of the argument catFile leads to sql injection.
This vulnerability is uniquely identified as CVE-2007-2599. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
USENIX Security ’23 – On the Feasibility of Malware Unpacking via Hardware-assisted Loop Profiling
1 year 6 months ago
Authors/Presenters:Binlin Cheng, Erika A Leal, Haotian Zhang, Jiang Mingy
Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the organizations YouTube channel.
The post USENIX Security ’23 – On the Feasibility of Malware Unpacking via Hardware-assisted Loop Profiling appeared first on Security Boulevard.
Marc Handelman
顺风车司机初体验:劝退油车通勤人士
1 year 6 months ago
顺风车原本是一个极其理想的「共享经济」模型,却因为监管、安全等多种不可控因素而酿成悲剧,甚至一度消失在人们的视野之中。近几年,我发现各大平台又重新上线了顺风车产品,恰好我又因为特殊原因,需要接受半
名为Hadooken的新型Linux恶意软件以Oracle WebLogic服务器为目标
1 year 6 months ago
安全客
Google Cloud 加强了备份和灾难恢复服务,通过不可修改的保险库为企业提供额外保护
1 year 6 months ago
安全客
云原生网络安全上升 17%,硬件下降 2%
1 year 6 months ago
安全客
Progress WhatsUp Gold 的严重漏洞在PoC发布后几小时就被利用
1 year 6 months ago
安全客
TrickMo Android 木马利用辅助功能服务进行设备银行欺诈
1 year 6 months ago
安全客
苹果 Vision Pro 漏洞导致虚拟键盘输入暴露给攻击者
1 year 6 months ago
安全客
“AI 教母”以 10 亿美元估值携 2.3 亿美元资金启动 World Labs
1 year 6 months ago
安全客
Fortinet 通过第三方确认客户数据泄露
1 year 6 months ago
安全客