Aggregator
LEGO's website hacked to push cryptocurrency scam
1 year 5 months ago
On Friday night, cryptocurrency scammers briefly hacked the LEGO website to promote a fake Lego token that could be purchased with Ethereum. [...]
Lawrence Abrams
实战中的高版本JDK的JNDI注入
1 year 5 months ago
CVE-2023-33008 | Apache Johnzon up to 1.2.20 JSON deserialization (JOHNZON-397)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Apache Johnzon up to 1.2.20. This issue affects some unknown processing of the component JSON Handler. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2023-33008. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-32200 | Apache Jena up to 4.8.0 Script Engine Expression information disclosure
1 year 5 months ago
A vulnerability was found in Apache Jena up to 4.8.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Script Engine Expression Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2023-32200. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-36037 | Zoho ManageEngine ADAudit Plus up to 7260 improper authorization
1 year 5 months ago
A vulnerability classified as problematic was found in Zoho ManageEngine ADAudit Plus up to 7260. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization.
This vulnerability is known as CVE-2024-36037. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41722 | goTenna Pro ATAK Plugin up to 1.9.12 Message weak authentication (icsa-24-270-05)
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in goTenna Pro ATAK Plugin up to 1.9.12. Affected is an unknown function of the component Message Handler. The manipulation leads to weak authentication.
This vulnerability is traded as CVE-2024-41722. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-43694 | goTenna Pro ATAK Plugin up to 1.9.12 sensitive information (icsa-24-270-05)
1 year 5 months ago
A vulnerability classified as problematic was found in goTenna Pro ATAK Plugin up to 1.9.12. Affected by this vulnerability is an unknown functionality. The manipulation leads to insecure storage of sensitive information.
This vulnerability is known as CVE-2024-43694. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-43814 | goTenna Pro ATAK Plugin up to 1.9.12 insertion of sensitive information into sent data (icsa-24-270-05)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in goTenna Pro ATAK Plugin up to 1.9.12. Affected by this issue is some unknown functionality. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is handled as CVE-2024-43814. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-45374 | goTenna Pro ATAK Plugin up to 1.9.12 weak password (icsa-24-270-05)
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in goTenna Pro ATAK Plugin up to 1.9.12. This affects an unknown part. The manipulation leads to weak password requirements.
This vulnerability is uniquely identified as CVE-2024-45374. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-43108 | goTenna Pro ATAK Plugin up to 1.9.12 integrity check (icsa-24-270-05)
1 year 5 months ago
A vulnerability has been found in goTenna Pro ATAK Plugin up to 1.9.12 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to missing support for integrity check.
This vulnerability was named CVE-2024-43108. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-7318 | Keycloak One Time Passcode a key past its expiration date
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Keycloak. Affected is an unknown function of the component One Time Passcode. The manipulation leads to use of a key past its expiration date.
This vulnerability is traded as CVE-2024-7318. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
GorillaBot Goes Ape With 300K Cyberattacks Worldwide
1 year 5 months ago
Among those affected by all this monkeying around with DDoS in September were some 4,000 organizations in the US.
Jai Vijayan, Contributing Writer
CVE-2014-7475 | Drifty Ionic View 0.0.2 X.509 Certificate cryptographic issues (VU#582497)
1 year 5 months ago
A vulnerability was found in Drifty Ionic View 0.0.2. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7475. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
Ukrainian pleads guilty to operating Raccoon Stealer malware
1 year 5 months ago
Ukrainian national Mark Sokolovsky has pleaded guilty to his involvement in the Raccoon Stealer malware-as-a-service (MaaS) cybercrime operation. [...]
Sergiu Gatlan
2024-10-07 - Data dump (Formbook, possible Astaroth/Guildma, Redline Stealer, unidentified malware)
1 year 5 months ago
CVE-2024-45060 | PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0 45_Quadratic_equation_solver.php cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0. Affected by this issue is some unknown functionality of the file 45_Quadratic_equation_solver.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-45060. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45292 | PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0 javascript URL cross site scripting (GHSA-r8w8-74ww-j4wh)
1 year 5 months ago
A vulnerability classified as problematic was found in PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0. Affected by this vulnerability is an unknown functionality of the component javascript URL Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-45292. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45293 | PHPOffice PhpSpreadsheet up to 1.29.0/2.1.0 Excel Parser XmlScanner.php toUtf8 xml external entity reference (GHSA-6hwr-6v2f-3m88)
1 year 5 months ago
A vulnerability classified as problematic has been found in PHPOffice PhpSpreadsheet up to 1.29.0/2.1.0. Affected is the function toUtf8 of the file src/PhpSpreadsheet/Reader/Security/XmlScanner.php of the component Excel Parser. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2024-45293. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45291 | PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0 XLSX File setEmbedImages absolute path traversal
1 year 5 months ago
A vulnerability was found in PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0. It has been rated as problematic. This issue affects the function setEmbedImages of the component XLSX File Handler. The manipulation leads to absolute path traversal.
The identification of this vulnerability is CVE-2024-45291. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com