Aggregator
【安全圈】湖南网信办对某公司因数据泄露开出20万罚单
7 hours 8 minutes ago
【安全圈】知名开源监控系统Zabbix存在SQL 注入漏洞
7 hours 8 minutes ago
关于开展“清朗·网络平台算法典型问题治理”专项行动的通知
7 hours 10 minutes ago
安全客
CVE-2012-1027 | project-open 3.4.0/3.5.0.1-2 message cross site scripting (VU#732115 / XFDB-72952)
7 hours 15 minutes ago
A vulnerability classified as problematic was found in project-open 3.4.0/3.5.0.1-2. This vulnerability affects unknown code. The manipulation of the argument message leads to cross site scripting.
This vulnerability was named CVE-2012-1027. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2012-2420 | Intuit QuickBooks 2009/2010/2011/2012 HelpAsyncPluggableProtocol.dll information disclosure (VU#232979 / Nessus ID 58848)
7 hours 15 minutes ago
A vulnerability was found in Intuit QuickBooks 2009/2010/2011/2012. It has been declared as critical. This vulnerability affects unknown code in the library HelpAsyncPluggableProtocol.dll. The manipulation leads to information disclosure.
This vulnerability was named CVE-2012-2420. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2012-2440 | TP-Link 8840T Default Configuration access control (VU#834723 / XFDB-74624)
7 hours 15 minutes ago
A vulnerability classified as critical was found in TP-Link 8840T. This vulnerability affects unknown code of the component Default Configuration. The manipulation leads to improper access controls.
This vulnerability was named CVE-2012-2440. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2012-0253 | Demandmedia Pluck SiteLife up to 5.0.11 cb cross site scripting (VU#400619 / XFDB-74805)
7 hours 15 minutes ago
A vulnerability classified as problematic has been found in Demandmedia Pluck SiteLife up to 5.0.11. This affects an unknown part. The manipulation of the argument cb leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2012-0253. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-5171 | CyberLink Power2Go 7.0/8.0 memory corruption (VU#158003 / EDB-18220)
7 hours 15 minutes ago
A vulnerability was found in CyberLink Power2Go 7.0/8.0. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2011-5171. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
新型 Ymir 勒索软件利用内存进行隐蔽攻击;目标是企业网络
7 hours 19 minutes ago
安全客
Право на приватность против корпоративного контроля: сотрудник Apple идёт в суд
7 hours 23 minutes ago
Суд рассмотрит обвинения в слежке и ограничении свободы слова.
CVE-2024-47476 | Dell NetWorker Management Console 19.11 signature verification (dsa-2024-477)
7 hours 28 minutes ago
A vulnerability was found in Dell NetWorker Management Console 19.11. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper verification of cryptographic signature.
The identification of this vulnerability is CVE-2024-47476. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-3474 | Bazel up to 4.2.2/5.3.1 Remote Assets API insufficiently protected credentials (GHSA-mxr8-q875-rhwq / Nessus ID 212014)
7 hours 34 minutes ago
A vulnerability was found in Bazel up to 4.2.2/5.3.1. It has been declared as problematic. This vulnerability affects unknown code of the component Remote Assets API. The manipulation leads to insufficiently protected credentials.
This vulnerability was named CVE-2022-3474. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-24031 | Facebook Zstandard up to 1.4.0 permission (Nessus ID 212015)
7 hours 34 minutes ago
A vulnerability was found in Facebook Zstandard up to 1.4.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2021-24031. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-24032 | Facebook Zstandard up to 1.4.8 permission (Nessus ID 212015)
7 hours 34 minutes ago
A vulnerability was found in Facebook Zstandard up to 1.4.8. It has been classified as critical. This affects an unknown part. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2021-24032. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-28361 | Storage Performance Development Kit up to 20.01.00 PDU null pointer dereference (Nessus ID 212016)
7 hours 34 minutes ago
A vulnerability has been found in Storage Performance Development Kit up to 20.01.00 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component PDU Handler. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2021-28361. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
新的 Glove Stealer 恶意软件绕过 Google Chrome 的应用程序绑定来窃取数据
7 hours 36 minutes ago
安全客
CVE-2009-3750 | Santostefano Giovanni ToyLog 0.1 read.php idm sql injection (EDB-9109 / XFDB-51633)
7 hours 43 minutes ago
A vulnerability, which was classified as critical, has been found in Santostefano Giovanni ToyLog 0.1. This issue affects some unknown processing of the file read.php. The manipulation of the argument idm leads to sql injection.
The identification of this vulnerability is CVE-2009-3750. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-3543 | phenotype CMS up to 2.8 login.php user sql injection (EDB-9107 / XFDB-51634)
7 hours 43 minutes ago
A vulnerability was found in phenotype CMS up to 2.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file phenotype/admin/login.php. The manipulation of the argument user leads to sql injection.
This vulnerability is handled as CVE-2009-3543. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-3757 | Citrix XenCenterWeb username cross site scripting (EDB-9106 / XFDB-51575)
7 hours 43 minutes ago
A vulnerability classified as problematic has been found in Citrix XenCenterWeb. Affected is an unknown function. The manipulation of the argument username leads to cross site scripting.
This vulnerability is traded as CVE-2009-3757. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com