Aggregator
APT73
10 months 1 week ago
cohenido
CVE-2025-24971 | DumbWareio DumbDrop /upload/init os command injection (GHSA-rx8m-jqm7-vcgp)
10 months 1 week ago
A vulnerability was found in DumbWareio DumbDrop. It has been rated as very critical. Affected by this issue is some unknown functionality of the file /upload/init. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2025-24971. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-0451 | Google Chrome up to 132.0.6834.159 Extensions API ui layer (ID 400610 / Nessus ID 214952)
10 months 1 week ago
A vulnerability was found in Google Chrome. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Extensions API. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is known as CVE-2025-0451. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-0951 | Adobe Photoshop CC memory corruption (EDB-39429 / Nessus ID 88718)
10 months 1 week ago
A vulnerability classified as critical has been found in Adobe Photoshop CC. Affected is an unknown function. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2016-0951. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Crypto-stealing apps found in Apple App Store for the first time
10 months 1 week ago
A new campaign dubbed 'SparkCat' has been uncovered, targeting the cryptocurrency wallet recovery phrases of Android and iOS users using optical character recognition (OCR) stealers. [...]
Bill Toulas
Google Play, Apple App Store apps caught stealing crypto wallets
10 months 1 week ago
A new campaign dubbed 'SparkCat' has been uncovered, targeting the cryptocurrency wallet recovery phrases of Android and iOS users using optical character recognition (OCR) stealers. [...]
Bill Toulas
A Threat Actor Claims to have Leaked a 2023 Breach of BodyWeb
10 months 1 week ago
A Threat Actor Claims to have Leaked a 2023 Breach of BodyWeb
Dark Web Informer - Cyber Threat Intelligence
CVE-2012-0151 | Microsoft Windows 7/Server 2003/Server 2008/Vista/XP Windows Authenticode Signature Verification WinVerifyTrust Signature input validation (MS12-024 / Nessus ID 58656)
10 months 1 week ago
A vulnerability was found in Microsoft Windows 7/Server 2003/Server 2008/Vista/XP. It has been classified as critical. Affected is an unknown function of the component Windows Authenticode Signature Verification. The manipulation as part of WinVerifyTrust Signature leads to improper input validation.
This vulnerability is traded as CVE-2012-0151. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2015-4852 | Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar command injection (Exploit 152268 / EDB-42806)
10 months 1 week ago
A vulnerability was found in Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the file oracle_common/modules/com.bea.core.apache.commons.collections.jar of the component WLS Security Handler. The manipulation leads to command injection.
This vulnerability is known as CVE-2015-4852. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2016-7193 | Microsoft Office up to 2016 memory corruption (MS16-121 / Nessus ID 94016)
10 months 1 week ago
A vulnerability classified as critical was found in Microsoft Office up to 2016. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2016-7193. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2016-8735 | Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11 JmxRemoteLifecycleListener access control (Nessus ID 900019 / ID 169430)
10 months 1 week ago
A vulnerability classified as very critical was found in Apache Tomcat up to 6.0.47/7.0.72/8.0.38/8.5.6/9.0.0.M11. Affected by this vulnerability is an unknown functionality of the component JmxRemoteLifecycleListener. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2016-8735. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-0146 | Microsoft Windows up to XP SP3 SMB input validation (MS17-010 / EDB-41891)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows. This issue affects some unknown processing of the component SMB. The manipulation leads to improper input validation (EternalBlue/EternalChampion/EternalRomance/EternalSynergy).
The identification of this vulnerability is CVE-2017-0146. The attack may be initiated remotely. Furthermore, there is an exploit available.
A worm is spreading, which is automatically exploiting this vulnerability.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2015-4852 | Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 WebLogic Server command injection (EDB-42806 / Nessus ID 87432)
10 months 1 week ago
A vulnerability classified as very critical has been found in Oracle StorageTek Tape Analytics SW Tool up to 2.2.0. This affects an unknown part of the component WebLogic Server. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2015-4852. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-8735 | Oracle Database Server 12.2.0.1 WLM access control (Nessus ID 900019 / ID 169430)
10 months 1 week ago
A vulnerability was found in Oracle Database Server 12.2.0.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component WLM. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2016-8735. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-0232 | Microsoft Windows up to XP SP3 NtVdmControl access control (MS10-015 / Nessus ID 44425)
10 months 1 week ago
A vulnerability was found in Microsoft Windows up to XP SP3. It has been rated as critical. Affected by this issue is the function NtVdmControl. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2010-0232. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-1347 | Microsoft Internet Explorer 8 'vtable' code injection (Advisory 2847140 / EDB-25294)
10 months 1 week ago
A vulnerability was found in Microsoft Internet Explorer 8. It has been classified as critical. This affects the function mshtml!CGenericElement::'vtable'. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2013-1347. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. Due to its background and reception, this vulnerability has an historic impact.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-6282 | Linux Kernel up to 3.5.4 on ARM v6k/v7 API Function get_user/put_user input validation (QCIR-2013-00010-1 / EDB-31574)
10 months 1 week ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 3.5.4 on ARM v6k/v7. Affected is the function get_user/put_user of the component API Function Handler. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2013-6282. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Secure by Design and Secure by Default: Why you need both for AppSec
10 months 1 week ago
The relationship between the two software security initiatives promoted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) can be misunderstood. Sometimes Secure by Design and Secure by Default are even pitted against each other. The reality is, though, that they are complementary approaches to security.
The post Secure by Design and Secure by Default: Why you need both for AppSec appeared first on Security Boulevard.
John P. Mello Jr.
RansomHub
10 months 1 week ago
cohenido