Aggregator
CVE-2024-41247 | Kashipara Responsive School Management System 3.2.0 New Class /smsa/add_class.php access control
CVE-2024-41248 | Kashipara Responsive School Management System 3.2.0 New Subject /smsa/add_subject.php access control
CVE-2024-41252 | Kashipara Responsive School Management System 3.2.0 Student Registration admin_student_register_approval.php access control
CVE-2024-41251 | Kashipara Responsive School Management System 3.2.0 Teacher Registration admin_teacher_register_approval.php access control
Tenable Adds Ability to Prioritize Vulnerabilities by Threat Level
Tenable this week at the Black Hat USA 2024 conference added an ability to identify the vulnerabilities in an IT environment that should be remediated first based on the actual threat they represent.
The post Tenable Adds Ability to Prioritize Vulnerabilities by Threat Level appeared first on Security Boulevard.
Valve 也许在开发《半条命3》
CVE-2024-42247 | Linux Kernel up to 5.10.221/5.15.162/6.1.99/6.6.40/6.9.9 allowedips swap_endian memory corruption
CVE-2024-42244 | Linux Kernel up to 5.10.221/5.15.162/6.1.99/6.6.40/6.9.9 mos7840 usb_kill_urb denial of service
CVE-2024-42242 | Linux Kernel up to 6.9.9 sdhci blk_queue_max_segment_size memory corruption (bf78b1accef4/63d20a94f24f)
CVE-2024-42240 | Linux Kernel up to 5.15.162/6.1.99/6.6.40/6.9.9 entry_SYSENTER_compat memory corruption
CVE-2024-42239 | Linux Kernel up to 6.6.40/6.9.9 bpf bpf_timer_cancel deserialization (936983051868/3e4e8178a866/d4523831f07a)
CVE-2024-42233 | Linux Kernel up to 6.9.9 pte_offset_map use after free (6a6c2aec1a89/24be02a42181)
CVE-2024-42245 | Linux Kernel up to 6.1.99/6.6.40/6.9.9 detach_tasks iteration
CVE-2024-42232 | Linux Kernel up to 6.9.9 libceph delayed_work use after free
CVE-2024-42241 | Linux Kernel up to 6.6.40/6.9.9 lib/xarray.c allocation of resources (93893eacb372/cd25208ca9b0/9fd154ba926b)
CVE-2024-42243 | Linux Kernel up to 6.6.40/6.9.9 lib/xarray.c allocation of resources (a0c42ddd0969/333c5539a31f/099d90642a71)
MSRC 2024 Most Valuable Security Researchers - Angelboy
We’re thrilled to announce that Angelboy, senior security researcher at DEVCORE, is named one of Microsoft’s MSRC 2024 Most Valuable Security Researchers! He not only secured the #33 spot on the overall list but also achieved the #9 position in the Windows category.
This is the first time Angelboy has been shortlisted on this annual leaderboard, and he is also the highest-ranked Taiwanese security researcher featured. This prestigious accomplishment highlights his exceptional expertise and significant contributions to the field.
The Microsoft Security Response Center (MSRC) has long recognized the efforts of security researchers who partner with Microsoft in reporting vulnerabilities through its Microsoft Researcher Recognition Program (MRRR). The program expresses gratitude for their contributions to the security of Microsoft’s global customers and products.
The MSRC 2024 Most Valuable Security Researchers list, announced on August 7th, is based on the total number of points the researchers earned for each valid report from July 2023 to June 2024. Angelboy secured the #33 spots on the leaderboard. Specifically, his dedicated passion for Windows Kernel research earned him a #9 ranking in the Windows category, placing him in the TOP 10. He was also awarded “Accuracy” and “Volume” badges, further highlighting his significant contributions to vulnerability research.
References:
Angelboy 入列微軟 MSRC 2024 前百大最有價值資安研究員!
恭喜 DEVCORE 資深資安研究員 Angelboy 榮獲 Microsoft 的 MSRC 2024 Most Valuable Security Researchers 的殊榮!除了在不分項 TOP 100 名單中榮獲 #33 名,在 Angelboy 長年研究的 Windows 領域中,他更以 #9 的名次擠入前十大行列。
這不僅是 Angelboy 首次登上該年度榜單,同時也是該名單中排名最高的台灣資安研究員。
Microsoft 旗下的 Microsoft Security Response Center(MSRC,或稱 Microsoft 安全性回應中心)長期藉 Microsoft Researcher Recognition Program(MRRR)計畫,公開表揚協助 Microsoft 挖掘系統安全漏洞的資安研究員,以此致謝優秀資安研究員為 Microsoft 的客戶及產品安全所付出的努力。
Microsoft 於 7 日公布的 MSRC 2024 Most Valuable Security Researchers 名單,是根據 2023 年 7 月至 2024 年 6 月,全球各地資安研究員向 MSRC 回報的漏洞得分所統計而得。在整體不分項名單中,Angelboy 獲得了 #33 名的殊榮。而針對 Microsoft 旗下各類型產品的 Windows 類別中,Angelboy 則入列 TOP 10,獲得 #9 的成績,並經認證全數漏洞回報皆為有效回報。
再次恭喜 Angelboy 奪得此一殊榮!
參考資料:
SecWiki News 2024-08-07 Review
更多最新文章,请访问SecWiki