Aggregator
CVE-2022-36362 | Siemens LOGO 8 BM IP Address input validation (ssa-955858 / EUVD-2022-39077)
2 days 2 hours ago
A vulnerability, which was classified as critical, was found in Siemens LOGO 8 BM. This vulnerability affects unknown code of the component IP Address Handler. Such manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2022-36362. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2022-36363 | Siemens LOGO 8 BM TCP Packet improper validation of specified index, position, or offset in input (ssa-955858 / EUVD-2022-39078)
2 days 2 hours ago
A vulnerability categorized as problematic has been discovered in Siemens LOGO 8 BM. This impacts an unknown function of the component TCP Packet Handler. Such manipulation leads to improper validation of specified index, position, or offset in input.
This vulnerability is listed as CVE-2022-36363. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2022-36361 | Siemens LOGO 8 BM TCP Packet buffer overflow (ssa-955858 / EUVD-2022-39076)
2 days 2 hours ago
A vulnerability was found in Siemens LOGO 8 BM. It has been rated as critical. This affects an unknown function of the component TCP Packet Handler. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2022-36361. The attack is only possible within the local network. No exploit exists.
vuldb.com
Firefox 用 Zlib 的 Rust 语言版本替代了 C 语言版本
2 days 2 hours ago
Firefox 浏览器从 v151 开始,Gzip 压缩/解压缩就依赖于 zlib-rs 库,用 Rust 语言开发的版本替代了 C 语言版本改进了性能,提供了更好的内存安全性,以及带来了英特尔第 13 代/第 14 代酷睿 CPU 不稳定导致的崩溃问题。致力于用 Rust 语言重写关键库的非盈利组织 Trifecta Tech Foundation 在 2024 年夏天就与 Mozilla 讨论在浏览器中集成 zlib-rs,但从测试到落地花了两年时间,一个重要原因就是 zlib-rs 触发了臭名昭著的英特尔 CPU bug。测试中 zlib-rs 中的一些代码导致英特尔 Raptor Lake CPU 频繁崩溃,开发者最终发现问题与 Huffman 编码写入内存的一个特定指令相关,识别问题之后解决起来就容易了,开发者通过加入一段“不安全代码”修复了该问题。
Warner warns of CISA cuts, staffing gaps in letter to acting chief
2 days 2 hours ago
Warner on Tuesday also wrote a letter to DHS Secretary Markwayne Mullin, underscoring that DHS must prioritize CISA and pay for the MS-ISAC.
The Top 10 Attack Surface Exposures in 2026
2 days 2 hours ago
Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk.
With time-to-exploit now down to a
The Hacker News
CVE-2022-36360 | Siemens LOGO 8 BM up to 8.2 Firmware Update data authenticity (ssa-928782 / EUVD-2022-39075)
2 days 2 hours ago
A vulnerability was found in Siemens LOGO 8 BM up to 8.2. It has been declared as critical. The impacted element is an unknown function of the component Firmware Update Handler. The manipulation results in insufficient verification of data authenticity.
This vulnerability is identified as CVE-2022-36360. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-36337 | Insyde Kernel up to 5.5 MebxConfiguration Driver stack-based overflow (EUVD-2022-39053)
2 days 2 hours ago
A vulnerability categorized as critical has been discovered in Insyde Kernel up to 5.5. This affects an unknown function of the component MebxConfiguration Driver. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2022-36337. The attack is only possible within the local network. No exploit exists.
vuldb.com
CVE-2022-36320 | Mozilla Firefox up to 102 memory corruption (EUVD-2022-39036)
2 days 2 hours ago
A vulnerability has been found in Mozilla Firefox up to 102 and classified as critical. This affects an unknown part. Performing a manipulation results in memory corruption.
This vulnerability was named CVE-2022-36320. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2022-36319 | Mozilla Thunderbird up to 102 CSS access control (Bug 1737722 / EUVD-2022-39035)
2 days 2 hours ago
A vulnerability was found in Mozilla Thunderbird up to 102. It has been classified as critical. This issue affects some unknown processing of the component CSS Handler. The manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2022-36319. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-36319 | Mozilla Firefox up to 102 CSS access control (Bug 1737722 / EUVD-2022-39035)
2 days 2 hours ago
A vulnerability marked as critical has been reported in Mozilla Firefox up to 102. The impacted element is an unknown function of the component CSS Handler. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2022-36319. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
威胁情报|Arch Linux AUR 供应链投毒关联恶意 npm 包分析
2 days 2 hours ago
本文分析了 Arch Linux AUR 供应链投毒事件,聚焦被篡改的 AUR 构建/安装脚本如何触发恶意 npm 包,并揭示其核心 ELF 载荷中的凭据采集、Tor onion C2 及 eBPF 隐身能力痕迹。
CVE-2025-40117 | Linux Kernel up to 6.17.2 misc pci_endpoint_test_ioctl buffer under-read (Nessus ID 298897 / WID-SEC-2025-2579)
2 days 2 hours ago
A vulnerability classified as critical was found in Linux Kernel up to 6.17.2. Affected is the function pci_endpoint_test_ioctl of the component Misc. Executing a manipulation can lead to buffer under-read.
This vulnerability is tracked as CVE-2025-40117. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-40116 | Linux Kernel up to 6.17.2 usb kthread_run null pointer dereference (Nessus ID 276782 / WID-SEC-2025-2579)
2 days 2 hours ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.17.2. This vulnerability affects the function kthread_run of the component usb. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-40116. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-40112 | Linux Kernel up to 6.17.2 return value (Nessus ID 276782 / WID-SEC-2025-2579)
2 days 2 hours ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17.2. The impacted element is an unknown function. The manipulation results in unchecked return value.
This vulnerability is known as CVE-2025-40112. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-40113 | Linux Kernel up to 6.17.2 remoteproc qcom_scm_pas_shutdown denial of service (Nessus ID 298897 / WID-SEC-2025-2579)
2 days 2 hours ago
A vulnerability identified as critical has been detected in Linux Kernel up to 6.17.2. This affects the function qcom_scm_pas_shutdown of the component remoteproc. This manipulation causes denial of service.
This vulnerability is handled as CVE-2025-40113. The attack can only be done within the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-40115 | Linux Kernel up to 6.17.2 mpt3sas ioc_info denial of service (Nessus ID 276782 / WID-SEC-2025-2579)
2 days 2 hours ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.17.2. This vulnerability affects the function ioc_info of the component mpt3sas. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2025-40115. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-40111 | Linux Kernel up to 6.17.3 vmwgfx vmw_execbuf_process use after free (Nessus ID 276782 / WID-SEC-2025-2579)
2 days 2 hours ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.17.3. The impacted element is the function vmw_execbuf_process of the component vmwgfx. This manipulation causes use after free.
This vulnerability appears as CVE-2025-40111. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-40110 | Linux Kernel up to 6.6.112/6.12.53/6.17.3 vmwgfx vmw_cmd_res_check null pointer dereference (EUVD-2025-106790 / Nessus ID 277808)
2 days 2 hours ago
A vulnerability classified as critical was found in Linux Kernel up to 6.6.112/6.12.53/6.17.3. The affected element is the function vmw_cmd_res_check of the component vmwgfx. The manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2025-40110. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
vuldb.com