Aggregator
CVE-2025-7700 | FFmpeg ALS Decoder libavcodec/alsdec.c null pointer dereference (Nessus ID 255189 / WID-SEC-2025-1583)
CVE-2024-31582 | FFmpeg 6.1 vf_codecview.c draw_block_rectangle buffer overflow (Nessus ID 255189)
一图看懂|山石网科2025半年报
CVE-2023-50008 | FFmpeg 6.1-3-g466799d4f5 libavutil/mem.c av_malloc buffer overflow (ID 10701 / Nessus ID 255189)
CVE-2020-15890 | LuaJIT up to 2.1.0-beta3 __gc out-of-bounds (Nessus ID 255190)
CVE-2020-24372 | LuaJIT up to 2.1.0-beta3 lj_err.c lj_err_run out-of-bounds (Nessus ID 255190)
CVE-2023-50007 | FFmpeg 6.1-3-g466799d4f5 thelibavutil/samplefmt.c theav_samples_set_silence buffer overflow (ID 10700 / Nessus ID 255189)
CVE-2019-19391 | LuaJIT up to 2.0.5 type confusion (Nessus ID 255190)
PhpSpreadsheet Library Vulnerability Lets Attackers Inject Malicious HTML Input
A critical Server-Side Request Forgery (SSRF) vulnerability has been discovered in the popular PhpSpreadsheet library, allowing attackers to inject malicious HTML input when processing spreadsheet documents. The vulnerability, assigned CVE-2025-54370, affects multiple versions of the phpoffice/phpspreadsheet package and carries a high severity rating with CVSS v3.1 score of 7.5 and CVSS v4.0 score of 8.7. Vulnerability Details The security flaw was discovered by Aleksey […]
The post PhpSpreadsheet Library Vulnerability Lets Attackers Inject Malicious HTML Input appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Encryption Backdoor in Military/Police Radios
【安全圈】WarLock勒索软件组织宣称攻击Colt电信公司,数据已被挂售
【安全圈】HOOK 木马进化:银行木马、间谍软件与勒索软件三位一体
【安全圈】Docker Desktop曝高危漏洞:恶意容器可劫持Windows主机
【安全圈】黑客动用上万IP,大规模扫描微软 RDP 服务
Users of WhatsApp Desktop on Windows Face Code Execution Risk Via Python
A critical security risk has emerged for Windows users of WhatsApp Desktop who also have Python installed. Attackers can exploit a flaw in how WhatsApp Desktop handles .pyz (Python archive) files, delivering arbitrary code execution on the victim’s machine with a single click. Researchers have discovered that a maliciously crafted .pyz file—normally used to bundle Python applications—can be disguised […]
The post Users of WhatsApp Desktop on Windows Face Code Execution Risk Via Python appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.