Aggregator
Meow
11 months ago
cohenido
Meow
11 months ago
cohenido
CVE-2014-7506 | imapp Realtime Music Rank 5.5 X.509 Certificate cryptographic issues (VU#582497)
11 months ago
A vulnerability classified as critical was found in imapp Realtime Music Rank 5.5. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-7506. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
Unlocking New DeFi Opportunities for BNB Holders
11 months ago
TORONTO, Ontario, October 8th, 2024/Chainwire/--clisBNB, developed by Lista DAO, is an innovative to
入侵物理隔离的系统,这家APT组织怎么做到的?
11 months ago
一家专门针对政府设施下手的APT组织已研发出了两套工具集,对已隔离系统展开了全方位攻势。
CVE-2016-3081 | Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1 command injection (EDB-39756 / Nessus ID 90773)
11 months ago
A vulnerability classified as very critical was found in Oracle MICROS Retail XBRi Loss Prevention up to 10.8.1. Affected by this vulnerability is an unknown functionality of the component Retail. The manipulation leads to command injection.
This vulnerability is known as CVE-2016-3081. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
微软 Word 曝“神奇Bug”,这样命名会直接删除文件
11 months ago
微软确认Word应用中存在一个“神奇的”Bug,可能导致用户在特定情况下错误地删除文件,影响所有使用Office 2024版本的用户。
巴西解除对 X 的屏蔽
11 months ago
在 X 满足巴西最高法院法官 Alexandre de Moraes 要求屏蔽其平台上被指传播虚假信息的账号、支付罚款和任命一名法律代表之后,巴西解除了对其的封锁。巴西是在 8 月 30 日下令封锁 X,此前 X 的所有者马斯克(Elon Musk)与大法官在言论自由、极右翼账户和虚假信息上展开了长达数个月的争执。巴西是 X 最大的市场之一,巴西有 2.13 亿人口,X 用户总数在 2000 万到 4000 万之间,在屏蔽 X 之后,替代微博客服务如 Bluesky 短时间内增加了数百万新用户。
30% of customer-facing APIs are completely unprotected
11 months ago
70% of customer-facing APIs are secured using HTTPS, leaving nearly one-third of these APIs completely unprotected, according to F5. This is a stark contrast to the 90% of web pages that are now accessed via HTTPS, following the push for secure web communications over the past decade. “APIs are becoming the backbone of digital transformation efforts, connecting critical services and applications across organizations,” said Lori MacVittie, Distinguished Engineer at F5. “However, as our report indicates, … More →
The post 30% of customer-facing APIs are completely unprotected appeared first on Help Net Security.
Help Net Security
CVE-2016-3081 | Apache Struts 2.0.0/2.3.24/2.3.28 Dynamic Method command injection (S2-032 / EDB-39756)
11 months ago
A vulnerability was found in Apache Struts 2.0.0/2.3.24/2.3.28. It has been rated as critical. Affected by this issue is some unknown functionality of the component Dynamic Method Handler. The manipulation leads to command injection.
This vulnerability is handled as CVE-2016-3081. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-1677 | Microsoft Azure Kubernetes Service Pod Identity authentication spoofing
11 months ago
A vulnerability has been found in Microsoft Azure Kubernetes Service and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Pod Identity Handler. The manipulation leads to authentication bypass by spoofing.
This vulnerability is known as CVE-2021-1677. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-1680 | Microsoft Windows up to Server 2019 Diagnostics Hub Standard Collector privileges management
11 months ago
A vulnerability was found in Microsoft Windows. It has been declared as critical. This vulnerability affects unknown code of the component Diagnostics Hub Standard Collector. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2021-1680. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-1682 | Microsoft Windows up to Server 2019 Kernel privileges management
11 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows up to Server 2019. This affects an unknown part of the component Kernel. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2021-1682. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-1676 | Microsoft Windows up to Server 2019 NT Lan Manager Datagram Receiver Driver information disclosure
11 months ago
A vulnerability was found in Microsoft Windows. It has been classified as problematic. Affected is an unknown function of the component NT Lan Manager Datagram Receiver Driver. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2021-1676. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-1681 | Microsoft Windows up to 10 2004 WalletService privileges management
11 months ago
A vulnerability was found in Microsoft Windows up to 10 2004. It has been rated as critical. This issue affects some unknown processing of the component WalletService. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2021-1681. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2009-0961 | Apple iPhone OS up to 2.2.1 (HT3639 / EDB-33044)
11 months ago
A vulnerability, which was classified as problematic, was found in Apple iPhone OS up to 2.2.1. Affected is an unknown function. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2009-0961. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2016-3087 | Apache Struts up to 2.3.28 REST Plugin input validation (S2-033 / EDB-39919)
11 months ago
A vulnerability, which was classified as critical, was found in Apache Struts up to 2.3.28. This affects an unknown part of the component REST Plugin. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2016-3087. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
HBO 纪录片声称中本聪是 Peter Todd
11 months ago
10 月 8 日播出的 HBO 纪录片《Money Electric: The Bitcoin Mystery》声称中本聪就是前加拿大比特币开发者 Peter Todd。但纪录片上映前 Todd 在发送给 CoinDesk 的一封电子邮件中否认他就是神秘的比特币作者。在纪录片中,导演 Cullen Hoback 根据新旧线索得出了这一结论,他最后直接问 Todd 为什么对比特币有如此深刻的见解,Todd 回答说因为我是中本聪。然而 Todd 在给 CoinDesk 的邮件中表示他当然不是中本聪。比特币社区对 Todd 并不陌生,中本聪在 2010 年销声匿迹前 Todd 是少数与他有过公开交流的人,但 Todd 此前未被怀疑就是中本聪本人。Todd 现年 39 岁,毕业于加拿大多伦多 Ontario College of Art and Design,当中本聪首次发表比特币白皮书时 Todd 只有 23 岁。
CVE-2016-3096 | Red Hat Ansible up to 1.9.6/2.0.1.x /opt/.lxc-attach-script create_script input validation (FEDORA-2016-28ff51a3f5 / Nessus ID 90606)
11 months ago
A vulnerability was found in Red Hat Ansible up to 1.9.6/2.0.1.x and classified as critical. Affected by this issue is the function create_script of the file /opt/.lxc-attach-script. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2016-3096. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com