SANS Internet Storm Center显示当前威胁级别为绿色,值班员为Guy Bruneau。页面包含播客ISC Stormcast(2025年8月8日)、即将举办的"Application Security: Securing Web Apps, APIs, and Microservices"课程(拉斯维加斯,2025年9月22日至27日)及网站导航信息。
A vulnerability was found in IBM QRadar Suite Software and Cloud Pak for Security up to 1.10.21.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper validation of specified type of input.
This vulnerability is handled as CVE-2023-47726. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Allegra. It has been rated as critical. Affected by this issue is the function unzipFile. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-5581. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Allegra. This affects the function renderFieldMatch. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2024-5579. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Allegra. This vulnerability affects the function loadFieldMatch. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-5580. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Trimble SketchUp 13.0.4124/24.0.553/2024.0.2 and classified as critical. This issue affects some unknown processing of the component SKP File Parser. The manipulation leads to uninitialized pointer.
The identification of this vulnerability is CVE-2025-2024. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Samsung SmartThings 000.054.00013. It has been classified as very critical. Affected is an unknown function of the component Hub Local API Service. The manipulation leads to improper verification of cryptographic signature.
This vulnerability is traded as CVE-2025-2233. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability, which was classified as critical, has been found in GitLab Enterprise Edition up to 17.7.6/17.8.4/17.9.1. Affected by this issue is some unknown functionality. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-8402. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in IrfanView. Affected is an unknown function of the component PNT File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2024-5874. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in IrfanView. Affected by this vulnerability is an unknown functionality of the component PIC File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2024-5877. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.