Aggregator
The Good, the Bad and the Ugly in Cybersecurity – Week 36
1 year 7 months ago
The Good | U.S. Officials Crackdown on Russian State-Backed Disinformation Campaigns Ahead of Presi
“Unstripping” binaries: Restoring debugging information in GDB with Pwndbg
1 year 7 months ago
By Jason AnGDB loses significant functionality when debugging binaries that lack
Cybersecurity Snapshot: RansomHub Group Triggers CISA Warning, While FBI Says North Korean Hackers Are Targeting Crypto Orgs
1 year 7 months ago
Cybersecurity teams must beware of RansomHub, a surging RaaS gang. Plus, North Korea has unleashed s
Cybersecurity Threat Briefing for Organizations Under the SOCI in Australia
1 year 7 months ago
September 06, 2024 3 Minute Read
CVE-2014-5922 | ga6748 1 X.509 Certificate cryptographic issues (VU#582497)
1 year 7 months ago
A vulnerability, which was classified as critical, was found in ga6748 1. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-5922. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2014-5921 | ea Need for Speed Network 1.0.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in ea Need for Speed Network 1.0.1. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-5921. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2007-2169 | Mozzers SubSystem up to 1.0 add.php memory corruption (EDB-3761 / XFDB-33739)
1 year 7 months ago
A vulnerability was found in Mozzers SubSystem up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2007-2169. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Transport for London staff faces systems disruptions after cyberattack
1 year 7 months ago
Transport for London, the city's public transportation agency, revealed today that its staff has limited access to systems and email due to measures implemented in response to a Sunday cyberattack. [...]
Sergiu Gatlan
Feds Warn on Russian Actors Targeting Critical Infrastructure
1 year 7 months ago
In the past, Putin's Unit 29155 has utilized malware like WhisperGate to target organizations, particularly those in Ukraine.
Dark Reading Staff
CISA Flags ICS Bugs in Baxter, Mitsubishi Products
1 year 7 months ago
The vulnerabilities affect industrial control tech used across the healthcare and critical manufacturing sectors.
Jai Vijayan, Contributing Writer
免费的爆款站长工具 Google Alerts:帮你精准监控品牌关键词、竞争对手和行业动态!
1 year 7 months ago
如果你还不知道 Google Alerts 这个站长工具,那你可能错过了一个可以大大提升工作效率的免费神器。作为一款由 Google 提供的服务,Google
CVE-2023-47473 | fuwushe iFair up to 23.8_ad0 path traversal
1 year 7 months ago
A vulnerability was found in fuwushe iFair up to 23.8_ad0. It has been classified as problematic. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2023-47473. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2023-51785 | Apache InLong up to 1.9.0 MySQL Driver deserialization
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in Apache InLong up to 1.9.0. Affected is an unknown function of the component MySQL Driver. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2023-51785. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-28816 | Student Information Chatbot 1.0 Login index.php username/password sql injection
1 year 7 months ago
A vulnerability was found in Student Information Chatbot 1.0. It has been classified as critical. Affected is an unknown function of the file index.php of the component Login. The manipulation of the argument username/password leads to sql injection.
This vulnerability is traded as CVE-2024-28816. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-2653 | amphp http up to 1.7.1/2.1.0 HTTP/2 CONTINUATION Frame memory allocation (GHSA-w8gf-g2vq-j2f4)
1 year 7 months ago
A vulnerability has been found in amphp http up to 1.7.1/2.1.0 and classified as critical. This vulnerability affects unknown code of the component HTTP2 CONTINUATION Frame Handler. The manipulation leads to uncontrolled memory allocation.
This vulnerability was named CVE-2024-2653. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52043 | D-Link COVR 1100 AC1200/COVR 1102 AC1200/COVR 1103 AC1200 Wireless Access Point Password improper authentication
1 year 7 months ago
A vulnerability classified as problematic was found in D-Link COVR 1100 AC1200, COVR 1102 AC1200 and COVR 1103 AC1200. This vulnerability affects unknown code of the component Wireless Access Point Password Handler. The manipulation leads to improper authentication.
This vulnerability was named CVE-2023-52043. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-27394 | Linux Kernel up to 6.8.8/6.9-rc5 tcp_ao_connect_init use after free (ca4fb6c6764b/80e679b352c3)
1 year 7 months ago
A vulnerability classified as critical was found in Linux Kernel up to 6.8.8/6.9-rc5. This vulnerability affects the function tcp_ao_connect_init. The manipulation leads to use after free.
This vulnerability was named CVE-2024-27394. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-28064 | Kiteworks Totemomail up to 8.2.x EnvelopeOpenServlet displayLoginChunkedImages/storeLoginChunkedImages messageId path traversal
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in Kiteworks Totemomail up to 8.2.x. Affected by this issue is the function displayLoginChunkedImages/storeLoginChunkedImages of the file /responsiveUI/EnvelopeOpenServlet. The manipulation of the argument messageId leads to path traversal.
This vulnerability is handled as CVE-2024-28064. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36523 | Wvp GB28181 Pro 2.0 access control (Issue 1456)
1 year 7 months ago
A vulnerability, which was classified as critical, was found in Wvp GB28181 Pro 2.0. Affected is an unknown function. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2024-36523. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com