Aggregator
【安全圈】用友U8CRM存在SQL注入漏洞
1 year 5 months ago
【安全圈】新规解读:《网络数据安全管理条例》
1 year 5 months ago
CVE-2024-47854 | Veritas Data Insight up to 7.0 HTTP Request cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Veritas Data Insight up to 7.0. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-47854. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
VoIP tab in NetworkMiner Professional
1 year 5 months ago
The VoIP tab is a unique feature only available in NetworkMiner Professional. The analyzed PcapNG file comes from a blog post by Johannes Weber titled VoIP Captures. See our NetworkMiner Professional tutorial videos for more tips and hints.
Erik Hjelmvik
ChatGPT 推出编程专用界面;特斯拉美国停售 Model 3 标续后驱版;问界针对 BBA 门店制定「特别计划」|极客早知道
1 year 5 months ago
OpenAI 推出了一种与 ChatGPT 交互的新方式:一种被称为「画布」的界面;Google在印度试点屏蔽部分侧载Android应用程序;问界针对 BBA(奔驰、宝马、奥迪)的门店制定了一项改建计划。
CVE-2014-7371 | Appearingbusiness Magic Balloonman Marty Boone 1.4 X.509 Certificate cryptographic issues (VU#582497)
1 year 5 months ago
A vulnerability classified as critical was found in Appearingbusiness Magic Balloonman Marty Boone 1.4. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-7371. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
Web3 Hustle: A Win-Win Venture
1 year 5 months ago
I ventured into the web3 ecosystem for the first time in 2020. It has been a turpsy-turvy journey up
38 секунд, которые стоят миллионов: как короткий клип изменил дискуссию о выборах
1 year 5 months ago
Один ролик вызвал волну дезинформации в соцсетях.
JVN: SUBNET Solutions製PowerSYSTEM Centerにおける複数の脆弱性
1 year 5 months ago
SUBNET Solutionsが提供するPowerSYSTEM Centerには、複数の脆弱性が存在します。
JVN: Delta Electronics製DIAEnergieにおける複数の脆弱性
1 year 5 months ago
Delta Electronicsが提供するDIAEnergieには、複数の脆弱性が存在します。
Dutch police breached by a state actor
1 year 5 months ago
Dutch police breached by a state actorThe Dutch government blames a “state actor” for hacking
From Tap-to-Earn to Play-to-Earn: How Hamster Kombat Is Fueling The Switch
1 year 5 months ago
To put it in proper context, Hamster Kombat (HMSTR)’s recent launch was quickly followed by a massiv
CVE-2016-6828 | Linux Kernel up to 4.7.4 SACK State include/net/tcp.h tcp_check_send_head use after free (EDB-40731 / Nessus ID 96478)
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 4.7.4. Affected is the function tcp_check_send_head of the file include/net/tcp.h of the component SACK State Handler. The manipulation leads to use after free.
This vulnerability is traded as CVE-2016-6828. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
North Korea ‘Shrouded Sleep’ malware campaign targeting Cambodia, other Southeast Asian nations
1 year 5 months ago
North Korean government hackers have targeted several Southeast Asian countries — even perceived al
CVE-2022-23132 | Zabbix Installation /var/run/zabbix access control (ZBX-20341 / Nessus ID 208100)
1 year 5 months ago
A vulnerability was found in Zabbix. It has been declared as critical. This vulnerability affects unknown code of the file /var/run/zabbix of the component Installation Handler. The manipulation leads to improper access controls.
This vulnerability was named CVE-2022-23132. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2023-31147 | c-ares DNS Query random values (GHSA-8r8p-23f3-64c2 / Nessus ID 208103)
1 year 5 months ago
A vulnerability classified as problematic was found in c-ares. This vulnerability affects unknown code of the component DNS Query Handler. The manipulation leads to insufficiently random values.
This vulnerability was named CVE-2023-31147. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2020-10177 | Pillow up to 6.2.2/7.0.0 libImaging/FliDecode.c out-of-bounds (Nessus ID 208107)
1 year 5 months ago
A vulnerability was found in Pillow up to 6.2.2/7.0.0 and classified as problematic. Affected by this issue is some unknown functionality of the file libImaging/FliDecode.c. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2020-10177. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-0881 | Oracle Transportation Management 6.4.3 Apache Xerces2 Java Parser denial of service (Nessus ID 208112)
1 year 5 months ago
A vulnerability was found in Oracle Transportation Management 6.4.3. It has been rated as critical. This issue affects some unknown processing of the component Apache Xerces2 Java Parser. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2012-0881. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20505 | Cisco ClamAV up to 1.4.0 PDF Parser out-of-bounds (Nessus ID 208113)
1 year 5 months ago
A vulnerability has been found in Cisco ClamAV and classified as problematic. Affected by this vulnerability is an unknown functionality of the component PDF Parser. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-20505. The attack can be launched remotely. There is no exploit available.
vuldb.com