Aggregator
50,000美元赏金:研究人员揭露严重的Zendesk电子邮件欺骗缺陷(CVE-2024-49193)
10 months 4 weeks ago
安全客
CVE-2019-15099 | Linux Kernel up to 5.2.8 Endpoint Descriptor usb.c null pointer dereference (USN-4258-1 / Nessus ID 208557)
10 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.2.8. Affected is an unknown function of the file drivers/net/wireless/ath/ath10k/usb.c of the component Endpoint Descriptor Handler. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2019-15099. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2019-15666 | Linux Kernel up to 5.0.18 Array Access net/xfrm/xfrm_user.c __xfrm_policy_unlink out-of-bounds (K53420251 / Nessus ID 208557)
10 months 4 weeks ago
A vulnerability has been found in Linux Kernel up to 5.0.18 and classified as critical. This vulnerability affects the function __xfrm_policy_unlink of the file net/xfrm/xfrm_user.c of the component Array Access. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2019-15666. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-19922 | Linux Kernel up to 5.3.8 Slice kernel/sched/fair.c resource consumption (Nessus ID 208557)
10 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 5.3.8. It has been declared as problematic. This vulnerability affects unknown code of the file kernel/sched/fair.c of the component Slice Handler. The manipulation leads to resource consumption.
This vulnerability was named CVE-2019-19922. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-15031 | Linux Kernel up to 5.2.14 on PowerPC process.c information disclosure (USN-4135-1 / Nessus ID 208557)
10 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.2.14 on PowerPC. Affected is an unknown function of the file arch/powerpc/kernel/process.c. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2019-15031. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2019-14867 | Ipa up to 4.6.6/4.7.3/4.8.2 Kerberos Key Data Parser ber_scanf resource consumption (RHSA-2020:0378 / Nessus ID 208558)
10 months 4 weeks ago
A vulnerability was found in Ipa up to 4.6.6/4.7.3/4.8.2. It has been classified as critical. This affects the function ber_scanf of the component Kerberos Key Data Parser. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2019-14867. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-14895 | Linux Kernel up to 3.x/4.17.x Marvell Wifi Chip Driver heap-based overflow (RHSA-2020:0328 / Nessus ID 208557)
10 months 4 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 3.x/4.17.x. Affected by this vulnerability is an unknown functionality of the component Marvell Wifi Chip Driver. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2019-14895. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-14901 | Linux Kernel up to 3.x/4.17.x Marvell Wifi Chip Driver resource consumption (RHSA-2020:0204 / Nessus ID 208557)
10 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 3.x/4.17.x. This affects an unknown part of the component Marvell Wifi Chip Driver. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2019-14901. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10195 | Ipa up to 4.6.6/4.7.3/4.8.2 Batch Processing Password information disclosure (RHSA-2020:0378 / Nessus ID 208558)
10 months 4 weeks ago
A vulnerability was found in Ipa up to 4.6.6/4.7.3/4.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Batch Processing. The manipulation leads to information disclosure (Password).
This vulnerability is handled as CVE-2019-10195. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-36385 | Linux Kernel up to 5.9 ucma.c ctx_list/ucma_migrate_id use after free (Nessus ID 208560)
10 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 5.9. It has been declared as critical. Affected by this vulnerability is the function ctx_list/ucma_migrate_id of the file drivers/infiniband/core/ucma.c. The manipulation leads to use after free.
This vulnerability is known as CVE-2020-36385. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CISSP和CompRIA Security+成为最受欢迎的安全证书
10 months 4 weeks ago
安全客
ReverseEngineering BLE Commands for Lamp
10 months 4 weeks ago
ANY.RUN’s Upgraded Linux Sandbox for Fast and Secure Malware Analysis
10 months 4 weeks ago
At ANY.RUN, we’re alwa
业务范围汇总及奖励机制汇总
10 months 4 weeks ago
Ubuntu Fixes Multiple PHP Vulnerabilities: Update Now
10 months 4 weeks ago
Multiple security vulnerabilities were identified in PHP, a widely-used open source general purpose
流行的Java安全框架“pac 4j”易受RCE攻击(CVE-2023-25581)
10 months 4 weeks ago
安全客
Randall Munroe’s XKCD ‘Ravioli-Shaped Objects’
10 months 4 weeks ago
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Ravioli-Shaped Objects’ appeared first on Security Boulevard.
Marc Handelman
富达投资今年遭遇第二次数据泄露
10 months 4 weeks ago
安全客
CVE-2022-1966 | Linux Kernel Netfilter Subsystem nf_tables_api.c use after free (Nessus ID 208562)
10 months 4 weeks ago
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is an unknown functionality of the file net/netfilter/nf_tables_api.c of the component Netfilter Subsystem. The manipulation leads to use after free.
This vulnerability is known as CVE-2022-1966. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com