Aggregator
科学家建立女性怀孕前后身体变化图谱
8 months 3 weeks ago
以色列魏茨曼研究所的研究人员使用了以色列最大的医疗服务机构时间跨度为 2003 年至 2020 年、20~35 岁未服用药物或患有慢性疾病的女性的匿名检测数据,分析了女性怀孕前、怀孕中和从怀孕到产后共一年多,这3个时间点的血液、尿液以及其他指标的匿名检测结果,以揭示女性怀孕和分娩的身体“代价”——从为供养胎儿所做的无数改变到产后身体的变化。研究人员收集了 76 项常见测试指标,包括胆固醇、免疫细胞、血红细胞、炎症情况以及肝脏、肾脏和新陈代谢的健康情况。结果发现,女性产后第一个月,76 个指标中的 47% 稳定在接近受孕前的值,有 41% 的指标需要 10 周以上的时间才能稳定下来,还有 12% 的指标则需要 4 到 10 周才能稳定下来。肝功和胆固醇需要大约 6 个月才能稳定,而骨骼和肝脏则需要一年时间才能达到健康指标。而包括炎症标志物和血液健康指标在内的几项指标,即使在 80 周后研究结束时,也没能恢复到受孕前的水平。研究人员指出,这种长期差异是由怀孕和分娩本身造成的,还是由孩子出生后的身体行为变化造成的,是未来需要研究的问题。
CVE-2025-31177 | gnuplot utf8_copy_one heap-based overflow
8 months 3 weeks ago
A vulnerability has been found in gnuplot and classified as critical. Affected by this vulnerability is the function utf8_copy_one. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2025-31177. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-28138 | TOTOLINK A800R 4.1.2cu.5137_B20200730 setNoticeCfg NoticeUrl privilege escalation
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setNoticeCfg. The manipulation of the argument NoticeUrl leads to privilege escalation.
This vulnerability is traded as CVE-2025-28138. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2516 | Kingsoft WPS Office 12.1.0.18276 on Windows Signature Verification inadequate encryption
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Kingsoft WPS Office 12.1.0.18276 on Windows. This issue affects some unknown processing of the component Signature Verification. The manipulation leads to inadequate encryption strength.
The identification of this vulnerability is CVE-2025-2516. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-30221 | Shopify pitchfork up to 0.10.x HTTP Response Header response splitting (GHSA-pfqj-w6r6-g86v)
8 months 3 weeks ago
A vulnerability classified as problematic was found in Shopify pitchfork up to 0.10.x. This vulnerability affects unknown code of the component HTTP Response Header Handler. The manipulation leads to http response splitting.
This vulnerability was named CVE-2025-30221. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29491 | libming 0.48 SWF File parseSWF_DEFINEBINARYDATA denial of service (Issue 330)
8 months 3 weeks ago
A vulnerability classified as problematic has been found in libming 0.48. This affects the function parseSWF_DEFINEBINARYDATA of the component SWF File Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-29491. The attack needs to be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-31181 | Red Hat Enterprise Linux 6/7/8 X11_graphics null pointer dereference
8 months 3 weeks ago
A vulnerability was found in Red Hat Enterprise Linux 6/7/8. It has been rated as critical. Affected by this issue is the function X11_graphics. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-31181. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2025-31180 | Red Hat Enterprise Linux 6/7/8 CANVAS_text null pointer dereference
8 months 3 weeks ago
A vulnerability was found in Red Hat Enterprise Linux 6/7/8. It has been declared as critical. Affected by this vulnerability is the function CANVAS_text. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2025-31180. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2025-31176 | Red Hat Enterprise Linux 6/7/8 plot3d_points null pointer dereference
8 months 3 weeks ago
A vulnerability was found in Red Hat Enterprise Linux 6/7/8. It has been classified as critical. Affected is the function plot3d_points. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2025-31176. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-31179 | Red Hat Enterprise Linux 6/7/8 xstrftime null pointer dereference
8 months 3 weeks ago
A vulnerability was found in Red Hat Enterprise Linux 6/7/8 and classified as critical. This issue affects the function xstrftime. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-31179. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-31178 | Red Hat Enterprise Linux 6/7/8 GetAnnotateString null pointer dereference
8 months 3 weeks ago
A vulnerability has been found in Red Hat Enterprise Linux 6/7/8 and classified as critical. This vulnerability affects the function GetAnnotateString. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2025-31178. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2025-29497 | libming 0.4.8 parseSWF_MORPHFILLSTYLES memory leak (Issue 330)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in libming 0.4.8. This affects the function parseSWF_MORPHFILLSTYLES. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2025-29497. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-29492 | libming 0.4.8 decompileSETVARIABLE memory corruption (Issue 330)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in libming 0.4.8. Affected by this issue is the function decompileSETVARIABLE. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2025-29492. The attack needs to be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-56469 | IBM UrbanCode Deploy/DevOps Deploy Agent Relay Service missing authentication
8 months 3 weeks ago
A vulnerability classified as critical was found in IBM UrbanCode Deploy and DevOps Deploy. Affected by this vulnerability is an unknown functionality of the component Agent Relay Service. The manipulation leads to missing authentication.
This vulnerability is known as CVE-2024-56469. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Cloud Attacks Raises by Five Times Attacking Sensitive IAM Service Accounts
8 months 3 weeks ago
Organizations are facing an unbelievable surge in cloud-based security threats, with attacks nearly five times more frequent at the end of 2024 compared to the beginning of the year. Most concerning is the targeted attack on Identity and Access Management (IAM) tokens, which security researchers describe as “holding the keys to the cloud kingdom.” The […]
The post Cloud Attacks Raises by Five Times Attacking Sensitive IAM Service Accounts appeared first on Cyber Security News.
Guru Baran
CVE-2025-21891 | Linux Kernel up to 6.1.129/6.6.80/6.12.17/6.13.5 IPv6 ipvlan_process_v6_outbound denial of service
8 months 3 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.129/6.6.80/6.12.17/6.13.5. Affected is the function ipvlan_process_v6_outbound of the component IPv6 Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-21891. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21888 | Linux Kernel up to 6.12.17/6.13.5 __mlx5_ib_dereg_mr privilege escalation
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.17/6.13.5. It has been rated as problematic. This issue affects the function __mlx5_ib_dereg_mr. The manipulation leads to privilege escalation.
The identification of this vulnerability is CVE-2025-21888. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-29494 | libming 0.4.8 SWF File decompileGETMEMBER memory corruption (Issue 330)
8 months 3 weeks ago
A vulnerability was found in libming 0.4.8. It has been declared as critical. This vulnerability affects the function decompileGETMEMBER of the component SWF File Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2025-29494. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-21882 | Linux Kernel up to 6.13.5 mlx5 privilege escalation
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.13.5. It has been classified as problematic. This affects an unknown part of the component mlx5. The manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2025-21882. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com