Aggregator
Emerging Threats & Vulnerabilities to Prepare for in 2025
8 months 1 week ago
From zero-day exploits to 5G network vulnerabilities, these are the threats that are expected to persist over the next 12 months.
Kristina Beek, Associate Editor, Dark Reading
Sometimes I cache: implementing lock-free probabilistic caching
8 months 1 week ago
If you want to know what cache revalidation is, how it works, and why it can involve rolling a die, read on. This blog post presents a lock-free probabilistic approach to cache revalidation, along
Thibault Meunier
CVE-2013-2890 | Linux Kernel LED State drivers/hid/hid-sony.c buzz_set_leds memory corruption (PATCH 04/14 / Nessus ID 80150)
8 months 1 week ago
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function buzz_set_leds of the file drivers/hid/hid-sony.c of the component LED State Handler. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2013-2890. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-2944 | strongSwan up to 5.0.2 improper authentication (dsa-2665 / Nessus ID 69030)
8 months 1 week ago
A vulnerability was found in strongSwan and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2013-2944. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2013-2977 | IBM Lotus Notes up to 9.0 PNG Image numeric error (swg21635878 / Nessus ID 66944)
8 months 1 week ago
A vulnerability classified as critical has been found in IBM Lotus Notes up to 9.0. Affected is an unknown function of the component PNG Image Handler. The manipulation leads to numeric error.
This vulnerability is traded as CVE-2013-2977. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-3005 | IBM AIX 6.1/7.1 tftp Client access control (tftp_fix / Nessus ID 67178)
8 months 1 week ago
A vulnerability was found in IBM AIX 6.1/7.1. It has been classified as critical. This affects an unknown part of the component tftp Client. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2013-3005. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-3004 | Oracle Utilities Framework up to 4.3.0.4 Common xml external entity reference (EDB-39205 / Nessus ID 79946)
8 months 1 week ago
A vulnerability was found in Oracle Utilities Framework up to 4.3.0.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component Common. The manipulation leads to xml external entity reference.
This vulnerability is handled as CVE-2014-3004. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-11022 | Oracle Agile PLM 9.3.6 Security cross site scripting (EDB-49766 / Nessus ID 209233)
8 months 1 week ago
A vulnerability has been found in Oracle Agile PLM 9.3.6 and classified as critical. This vulnerability affects unknown code of the component Security. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2020-11022. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-31885 | Marval MSM 14.19.0.12476 VBScript os command injection (EDB-50956)
8 months 1 week ago
A vulnerability was found in Marval MSM 14.19.0.12476. It has been classified as critical. This affects an unknown part of the component VBScript Handler. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2022-31885. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
Ruby 3.4 释出
8 months 1 week ago
Ruby 语言以在圣诞节这天发布重大更新闻名,今年的圣诞节当然也不例外,它释出了 Ruby 3.4。主要新特性包括:引入 it 用于引用一个没有变量名称的区块参数;默认解析器 Prism;socket 库支持 RFC 8305“Happy Eyeballs V2”;改进 YJIT just-in-time 代码性能,等等。
CVE-2024-12951 | 1000 Projects Portfolio Management System MCA 1.0 add_personal_details.php profile unrestricted upload
8 months 1 week ago
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /add_personal_details.php. The manipulation of the argument profile leads to unrestricted upload.
This vulnerability is traded as CVE-2024-12951. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-12952 | melMass comfy_mtb up to 0.1.4 Dependency comfy_mtb/endpoint.py run_command code injection
8 months 1 week ago
A vulnerability classified as critical was found in melMass comfy_mtb up to 0.1.4. Affected by this vulnerability is the function run_command of the file comfy_mtb/endpoint.py of the component Dependency Handler. The manipulation leads to code injection.
This vulnerability is known as CVE-2024-12952. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Тайны округа Блора: 82 ГБ государственных данных попали в лапы хакеров
8 months 1 week ago
Неизвестные проникли в защищённую систему регионального казначейства.
IL-23R: врачи научились измерять старение организма по одному белку
8 months 1 week ago
Изобретение Mayo распознает возрастные заболевания до первых симптомов.
CVE-1999-0174 | Netscape Communicator up to 4.51 view-source path traversal (EDB-20568 / Nessus ID 10294)
8 months 1 week ago
A vulnerability was found in Netscape Communicator up to 4.51. It has been classified as problematic. Affected is an unknown function of the component view-source. The manipulation leads to path traversal.
This vulnerability is traded as CVE-1999-0174. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
无言的宇宙
8 months 1 week ago
依稀往梦似曾见
Top Cybersecurity Compliance Issues Businesses Face Today
8 months 1 week ago
As organizations increasingly rely on digital infrastructure, the stakes have never been higher. Cybersecurity compliance is necessary to safeguard sensitive data, maintain customer trust, and avoid costly fines. With a constantly shifting threat landscape, evolving regulations, and the rise of new technologies, businesses must prioritize cybersecurity posture improvement to stay ahead of the curve. Assura… Continue reading Top Cybersecurity Compliance Issues Businesses Face Today
The post Top Cybersecurity Compliance Issues Businesses Face Today appeared first on Assura, Inc..
The post Top Cybersecurity Compliance Issues Businesses Face Today appeared first on Security Boulevard.
Assura Team
CVE-2003-0688 | Sendmail up to 8.12.8-4 DNS Mapper denial of service (VU#993452 / Nessus ID 14068)
8 months 1 week ago
A vulnerability classified as problematic has been found in Sendmail up to 8.12.8-4. This affects an unknown part of the component DNS Mapper. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2003-0688. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2003-0615 | Debian Linux 3.0 CGI.pm start_form action cross site scripting (VU#246409 / Nessus ID 15208)
8 months 1 week ago
A vulnerability was found in Debian Linux 3.0 and classified as problematic. This issue affects the function start_form of the file CGI.pm. The manipulation of the argument action leads to basic cross site scripting.
The identification of this vulnerability is CVE-2003-0615. The attack may be initiated remotely. There is no exploit available.
vuldb.com