Aggregator
CVE-2002-2021 | Woltlab Burning Board 1.1.1 message cross site scripting (EDB-21380 / XFDB-8841)
8 months ago
A vulnerability was found in Woltlab Burning Board 1.1.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument message leads to basic cross site scripting.
This vulnerability is known as CVE-2002-2021. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-1999-0046 | Sun Solaris 2.3/2.4/2.5/2.5.1 rlogin TERM memory corruption (EDB-19203 / XFDB-423)
8 months ago
A vulnerability has been found in Sun Solaris 2.3/2.4/2.5/2.5.1 and classified as very critical. Affected by this vulnerability is an unknown functionality of the component rlogin. The manipulation of the argument TERM as part of Environment Variable leads to memory corruption.
This vulnerability is known as CVE-1999-0046. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Don’t Clobber the Frame Pointer
8 months ago
This year in LLVM (2024)
8 months ago
« Back to article overview. 05. January 2025
Malicious npm packages target Ethereum developers
8 months ago
Malicious npm packages target Ethereum developers, impersonating Hardhat plugins to steal private keys and sensitive data. Hardhat, by the Nomic Foundation, is an essential Ethereum tool, enabling streamlined smart contract and dApp development with customizable plugins. Socket researchers reported a supply chain attack targeting the Nomic Foundation and Hardhat platforms, attackers use malicious npm packages to […]
Pierluigi Paganini
CVE-2006-5536 | D-Link DSL-G624T Firmware 3.00b01t01.ya C.2006-06-16 getpage path traversal (EDB-28847 / BID-20689)
8 months ago
A vulnerability was found in D-Link DSL-G624T Firmware 3.00b01t01.ya C.2006-06-16. It has been declared as problematic. This vulnerability affects unknown code of the component Firmware. The manipulation of the argument getpage leads to path traversal.
This vulnerability was named CVE-2006-5536. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-4492 | Apple Mac OS X 10.8.5/10.9.5/10.10/10.10.1 libnetcore data processing (HT204244 / EDB-35847)
8 months ago
A vulnerability was found in Apple Mac OS X 10.8.5/10.9.5/10.10/10.10.1. It has been declared as critical. This vulnerability affects unknown code of the component libnetcore. The manipulation leads to data processing error.
This vulnerability was named CVE-2014-4492. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-6608 | Elastix 2.3.0 Page cross site scripting (ID 118454 / EDB-38078)
8 months ago
A vulnerability, which was classified as problematic, was found in Elastix 2.3.0. This affects an unknown part. The manipulation of the argument Page leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2012-6608. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Daily Dose of Dark Web Informer - January 4th, 2025
8 months ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2023-22855 | Kardex Mlog MCC 5.7.12+0-a203c2a213-master Web Interface Path.Combine path traversal (Advisory 171046 / EDB-51239)
8 months ago
A vulnerability classified as critical has been found in Kardex Mlog MCC 5.7.12+0-a203c2a213-master. Affected is the function Path.Combine of the component Web Interface Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2023-22855. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2000-0669 | Novell NetWare 5.0 SMDR.NLM denial of service (EDB-20072 / BID-1467)
8 months ago
A vulnerability was found in Novell NetWare 5.0 and classified as problematic. This issue affects some unknown processing of the file SMDR.NLM. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2000-0669. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2013-6884 | Cru-inc Ditto Forensic Fieldstation prior 2013jun30a credentials management (Exploit 124420 / EDB-30396)
8 months ago
A vulnerability was found in Cru-inc Ditto Forensic Fieldstation. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to credentials management.
This vulnerability is known as CVE-2013-6884. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-1093 | 1024 CMS 2.1.1 rss.php id sql injection (EDB-14942 / BID-38476)
8 months ago
A vulnerability was found in 1024 CMS 2.1.1 and classified as critical. This issue affects some unknown processing of the file rss.php. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2010-1093. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Apple Settles 'Hey Siri' Lawsuit for $95 Million
8 months ago
Plaintiffs Sued After Report that Apple Eavesdropped on Intimate Moments
Apple agreed to pay $95 million to settle a lawsuit accusing the smart device giant of illegally recording audio through its Siri virtual assistant and sharing extracts with human reviewers. Class members who purchased Siri-enabled devices could receive $20 per device.
Apple agreed to pay $95 million to settle a lawsuit accusing the smart device giant of illegally recording audio through its Siri virtual assistant and sharing extracts with human reviewers. Class members who purchased Siri-enabled devices could receive $20 per device.
Nuclei flaw lets malicious templates bypass signature verification
8 months ago
A now-fixed vulnerability in the open-source vulnerability scanner Nuclei could potentially allow attackers to bypass signature verification while sneaking malicious code into templates that execute on local systems. [...]
Lawrence Abrams
Nuclei flaw bypasses template signature checks to execute commands
8 months ago
A now-fixed vulnerability in the open-source vulnerability scanner Nuclei could potentially allow attackers to bypass signature verification while sneaking malicious code into templates that execute on local systems. [...]
Lawrence Abrams
CVE-2020-35598 | Advanced Comment System 1.0 index.php ACS_path pathname traversal (EDB-49343)
8 months ago
A vulnerability was found in Advanced Comment System 1.0 and classified as critical. This issue affects some unknown processing of the file advanced_component_system/index.php. The manipulation of the argument ACS_path leads to pathname traversal.
The identification of this vulnerability is CVE-2020-35598. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Alleged Sale of Malware Toolkit (LNK + Fileless RAT/Loader)
8 months ago
Alleged Sale of Malware Toolkit (LNK + Fileless RAT/Loader)
Dark Web Informer - Cyber Threat Intelligence
CVE-2020-7991 | Adive Framework 2.0.8 cross-site request forgery (ID 156106 / EDB-47946)
8 months ago
A vulnerability was found in Adive Framework 2.0.8. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2020-7991. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com