Aggregator
Open Source Security Incidents Aren't Going Away
10 months ago
Companies and organizations need to recognize the importance of investing in engineers who possess both the soft and hard skills required to secure open source software effectively.
Michael Lieberman
CVE-2015-8222 | Ubuntu lxd prior 0.20-0ubuntu4.1 /var/lib/lxd/unix.socket access control (USN-2809-1 / ID 196310)
10 months ago
A vulnerability has been found in Ubuntu lxd and classified as problematic. This vulnerability affects unknown code in the library /var/lib/lxd/unix.socket. The manipulation leads to improper access controls.
This vulnerability was named CVE-2015-8222. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-7987 | mDNSResponder up to 625.41.1 rfc3110_import memory corruption (VU#143335 / BID-91323)
10 months ago
A vulnerability was found in mDNSResponder up to 625.41.1. It has been declared as very critical. Affected by this vulnerability is the function rfc3110_import. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2015-7987. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
【AI速读】下一个颠覆范式的威胁是什么?正确评估生成式人工智能对恐怖主义的潜在影响
10 months ago
黑客可通过系统漏洞访问马自达汽车控制装置
10 months ago
安全客
CVE-2015-7987 | mDNSResponder up to 625.41.1 GetValueForMACAddr memory corruption (VU#143335 / BID-91323)
10 months ago
A vulnerability was found in mDNSResponder up to 625.41.1. It has been classified as very critical. Affected is the function GetValueForMACAddr. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2015-7987. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
A new fileless variant of Remcos RAT observed in the wild
10 months ago
Fortinet researchers discovered a new phishing campaign spreading a variant of the commercial malware Remcos RAT. Fortinet’s FortiGuard Labs recently uncovered a phishing campaign spreading a new variant of the Remcos RAT. Remcos is a commercial remote administration tool (RAT) that is sold online to allow buyers remote control over computers. Threat actors use Remcos […]
Pierluigi Paganini
Veeam Backup & Replication 漏洞在新的 Frag 勒索软件攻击中被重复使用
10 months ago
安全客
CVE-2006-2887 | Aspburst myNewsletter 1.1.2 Login validatelogin.asp UserName sql injection (EDB-1884 / XFDB-26947)
10 months ago
A vulnerability, which was classified as critical, was found in Aspburst myNewsletter 1.1.2. Affected is an unknown function of the file validatelogin.asp of the component Login. The manipulation of the argument UserName leads to sql injection.
This vulnerability is traded as CVE-2006-2887. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Roblox开发人员受到恶意npm包的供应链攻击
10 months ago
安全客
美国机构提醒员工限制使用电话,因为 Salt Typhoon 黑客攻击了电信提供商
10 months ago
安全客
CVE-2024-50219 | Linux Kernel up to 5.15.170/6.1.115/6.6.59/6.11.6 Network Packet unreserve_highatomic_pageblock allocation of resources
10 months ago
A vulnerability was suspected in Linux Kernel up to 5.15.170/6.1.115/6.6.59/6.11.6. Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all.
vuldb.com
SpyNote 恶意软件:虚假防病毒软件在复杂的新活动中以 Android 用户为目标
10 months ago
安全客
CVE-2024-11079 | Red Hat Ansible hostvars Object information disclosure
10 months ago
A vulnerability classified as problematic was found in Red Hat Ansible. Affected by this vulnerability is an unknown functionality of the component hostvars Object Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-11079. The attack can only be done within the local network. There is no exploit available.
vuldb.com
QSC 恶意软件框架:CloudComputating Group 网络间谍武器库中的新工具
10 months ago
安全客
CVE-2024-10345 | Helix Core up to 2024.1 shutdown resource consumption
10 months ago
A vulnerability classified as critical has been found in Helix Core up to 2024.1. Affected is the function shutdown. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-10345. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34014 | Acronis Backup Plugin for cPanel & WHM on Linux symlink
10 months ago
A vulnerability was found in Acronis Backup Plugin for cPanel & WHM, Backup Extension for Plesk and Backup Plugin for DirectAdmin on Linux. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to symlink following.
The identification of this vulnerability is CVE-2024-34014. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34015 | Acronis Backup Plugin for cPanel & WHM up to 817 on Linux symlink
10 months ago
A vulnerability was found in Acronis Backup Plugin for cPanel & WHM up to 817 on Linux. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to symlink following.
This vulnerability was named CVE-2024-34015. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43429 | Moodle up to 4.1.11/4.2.8/4.3.5/4.4.1 Gradebook Report information disclosure
10 months ago
A vulnerability was found in Moodle up to 4.1.11/4.2.8/4.3.5/4.4.1. It has been classified as problematic. This affects an unknown part of the component Gradebook Report. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-43429. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com