Aggregator
Trinity
1 year ago
cohenido
BianLian
1 year ago
cohenido
Week in review: Exploitable flaws in corporate VPN clients, malware loader created with gaming engine
1 year ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Researchers reveal exploitable flaws in corporate VPN clients Researchers have discovered vulnerabilities in the update process of Palo Alto Networks (CVE-2024-5921) and SonicWall (CVE-2024-29014) corporate VPN clients that could be exploited to remotely execute code on users’ devices. Cybercriminals used a gaming engine to create undetectable malware loader Threat actors are using an ingenious new way for covertly delivering malware … More →
The post Week in review: Exploitable flaws in corporate VPN clients, malware loader created with gaming engine appeared first on Help Net Security.
Help Net Security
CVE-2009-2036 | Geekbill Open Biller 0.1 index.php username sql injection (EDB-8927 / OSVDB-55103)
1 year ago
A vulnerability was found in Geekbill Open Biller 0.1. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument username leads to sql injection.
The identification of this vulnerability is CVE-2009-2036. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2081 | phpWebThings up to 1.5.2 help.php module path traversal (EDB-8928 / BID-35313)
1 year ago
A vulnerability was found in phpWebThings up to 1.5.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file help.php. The manipulation of the argument module leads to path traversal.
This vulnerability is known as CVE-2009-2081. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2641 | Rich White School Data Nav page code injection (EDB-8924)
1 year ago
A vulnerability, which was classified as critical, has been found in Rich White School Data Nav. This issue affects some unknown processing. The manipulation of the argument page leads to code injection.
The identification of this vulnerability is CVE-2009-2641. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2642 | Desiscripts Desi Short URL Script 1.0 index.php improper authentication (EDB-8925)
1 year ago
A vulnerability, which was classified as critical, was found in Desiscripts Desi Short URL Script 1.0. Affected is an unknown function of the file index.php. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2009-2642. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2011 | dxstudio DX Studio Player prior 3.0.12.0 Javascript API shell.execute os command injection (EDB-8922 / XFDB-51035)
1 year ago
A vulnerability classified as very critical was found in dxstudio DX Studio Player. This vulnerability affects unknown code of the file shell.execute of the component Javascript API. The manipulation leads to os command injection.
This vulnerability was named CVE-2009-2011. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-2633 | Ordasoft Com Vehiclemanager 1.0 toolbar_ext.php mosConfig_absolute_path code injection (EDB-8920)
1 year ago
A vulnerability, which was classified as critical, was found in Ordasoft Com Vehiclemanager 1.0. This affects an unknown part of the file toolbar_ext.php. The manipulation of the argument mosConfig_absolute_path leads to code injection.
This vulnerability is uniquely identified as CVE-2009-2633. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
广汽华为将携手打造新品牌;马斯克申请禁令并指控 OpenAI;CES 展商遭大规模拒签 | 极客早知道
1 year ago
广汽华为将携手打造新品牌;马斯克申请禁令并指控 OpenAI;CES 展商遭大规模拒签 | 极客早知道
Hackers stole millions of dollars from Uganda Central Bank
1 year ago
Hackers stole millions of dollars from Uganda Central Bank
CVE-2014-4380 | Apple iOS up to 7.1.2 IOHIDFamily memory corruption (HT6441 / Nessus ID 77822)
1 year ago
A vulnerability classified as critical was found in Apple iOS up to 7.1.2. This vulnerability affects unknown code of the component IOHIDFamily. The manipulation leads to memory corruption.
This vulnerability was named CVE-2014-4380. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-4380 | Apple Mac OS X up to 10.9.3 IOHIDFamily memory corruption (HT6535 / Nessus ID 77822)
1 year ago
A vulnerability was found in Apple Mac OS X up to 10.9.3. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component IOHIDFamily. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2014-4380. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-4380 | Apple MacOS X up to 10.10.2 IOHIDFamily memory corruption (HT204659 / Nessus ID 77822)
1 year ago
A vulnerability classified as very critical has been found in Apple MacOS X up to 10.10.2. This affects an unknown part of the component IOHIDFamily. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2014-4380. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-4405 | Apple Mac OS X up to 10.9.3 IOHIDFamily null pointer dereference (HT6535 / Nessus ID 77822)
1 year ago
A vulnerability has been found in Apple Mac OS X up to 10.9.3 and classified as very critical. This vulnerability affects unknown code of the component IOHIDFamily. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2014-4405. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-4405 | Apple MacOS X up to 10.10.2 IOHIDFamily null pointer dereference (HT204659 / Nessus ID 77822)
1 year ago
A vulnerability was found in Apple MacOS X up to 10.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component IOHIDFamily. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2014-4405. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-6541 | Synacor Zimbra Collaboration 8.0.9 Interface cross-site request forgery (EDB-39500 / XFDB-111036)
1 year ago
A vulnerability classified as problematic has been found in Synacor Zimbra Collaboration 8.0.9. Affected is an unknown function of the component Interface. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2015-6541. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-5029 | Exhibitor Web UI up to 1.7.1 Config Editor os command injection (EDB-48654)
1 year ago
A vulnerability was found in Exhibitor Web UI up to 1.7.1. It has been classified as critical. This affects an unknown part of the component Config Editor. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2019-5029. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
飞越疯人院
1 year ago
你们以为你们是疯子吗