Aggregator
秘密恶意程序感染了数千 Linux 系统
11 months ago
研究人员报告一种秘密的挖矿恶意程序感染了数千台运行 Linux 的系统。该恶意程序至少从 2021 年开始传播,它利用愈 2 万个常见错误配置感染系统,还能利用去年修复的 Apache R
CVE-2001-0193 | Debian Linux 2.2/6.3/6.4/7.0 man -l format string (EDB-20604 / Nessus ID 14865)
11 months ago
A vulnerability classified as critical was found in Debian Linux 2.2/6.3/6.4/7.0. Affected by this vulnerability is an unknown functionality of the component man. The manipulation of the argument -l leads to format string.
This vulnerability is known as CVE-2001-0193. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Play
11 months ago
cohenido
Play
11 months ago
cohenido
CVE-2007-4757 | phpMytourney menu.php functions_file input validation (EDB-4368 / XFDB-36495)
11 months ago
A vulnerability classified as critical was found in phpMytourney. Affected by this vulnerability is an unknown functionality of the file menu.php. The manipulation of the argument functions_file leads to improper input validation.
This vulnerability is known as CVE-2007-4757. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-4024 | W1L3D4 Philboard 0.3 w1l3d4_aramasonuc.asp searchterms cross site scripting (EDB-30382 / XFDB-35598)
11 months ago
A vulnerability classified as problematic has been found in W1L3D4 Philboard 0.3. This affects an unknown part of the file w1l3d4_aramasonuc.asp. The manipulation of the argument searchterms leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2007-4024. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
How a Compromised NPM Package Revealed GitHub Workflow Vulnerabilities
11 months ago
In December 2023, it was discovered that an NPM package commonly used by decentralized web applicati
CVE-2016-4166 | Adobe Flash Player up to 21.0.0.242 privileges management (MS16-083 / Nessus ID 91671)
11 months ago
A vulnerability has been found in Adobe Flash Player up to 21.0.0.242 and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2016-4166. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
因中美紧张关系 Waymo 选择现代汽车的 Ioniq 5 作为其新一代的无人驾驶出租车
11 months ago
Waymo 宣布与现代汽车公司达成多年战略合作伙伴关系,将把该公司的自主驾驶系统整合到美制的现代 Ioniq 5 汽车中。新汽车预计会在 2025 年晚些时候进行路试,之后加入到其无人驾驶
CVE-2024-46830 | Linux Kernel up to 6.1.109/6.6.50/6.10.9 kvm_vcpu_ioctl_x86_set_vcpu_events null pointer dereference (Nessus ID 208099)
11 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.109/6.6.50/6.10.9. Affected is the function kvm_vcpu_ioctl_x86_set_vcpu_events. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-46830. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46828 | Linux Kernel up to 6.10.9 sch_cake array index (Nessus ID 208099)
11 months ago
A vulnerability classified as critical was found in Linux Kernel up to 6.10.9. Affected by this vulnerability is an unknown functionality of the component sch_cake. The manipulation leads to improper validation of array index.
This vulnerability is known as CVE-2024-46828. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46829 | Linux Kernel up to 6.10.9 rt_mutex_handle_deadlock (Nessus ID 208099)
11 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.10.9. This affects the function rt_mutex_handle_deadlock. The manipulation leads to deadlock.
This vulnerability is uniquely identified as CVE-2024-46829. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46822 | Linux Kernel up to 6.10.9 get_cpu_for_acpi_id null pointer dereference (Nessus ID 208099)
11 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.10.9. Affected by this issue is the function get_cpu_for_acpi_id. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-46822. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46818 | Linux Kernel up to 6.10.8 AMD Display gpio_id array index (Nessus ID 208099)
11 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.10.8. This affects the function gpio_id of the component AMD Display. The manipulation leads to improper validation of array index.
This vulnerability is uniquely identified as CVE-2024-46818. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46821 | Linux Kernel up to 6.1.108/6.6.49/6.10.8 AMD clk_idex array index (Nessus ID 208099)
11 months ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.1.108/6.6.49/6.10.8. Affected is the function clk_idex of the component AMD. The manipulation leads to improper validation of array index.
This vulnerability is traded as CVE-2024-46821. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46819 | Linux Kernel up to 5.10.225/5.15.166/6.1.108/6.6.49/6.10.8 AMD GPU nbio_v7_4 null pointer dereference (Nessus ID 208099)
11 months ago
A vulnerability has been found in Linux Kernel up to 5.10.225/5.15.166/6.1.108/6.6.49/6.10.8 and classified as critical. Affected by this vulnerability is the function nbio_v7_4 of the component AMD GPU. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-46819. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-4802 | Ourgame.com GlobalLink 2.7.0.8 ActiveX Control glitemcom.dll second memory corruption (EDB-4366 / XFDB-36501)
11 months ago
A vulnerability was found in Ourgame.com GlobalLink 2.7.0.8. It has been declared as critical. This vulnerability affects unknown code in the library glitemcom.dll of the component ActiveX Control. The manipulation of the argument second leads to memory corruption.
This vulnerability was named CVE-2007-4802. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46814 | Linux Kernel up to 5.10.225/5.15.166/6.1.108/6.6.49/6.10.8 AMD Display msg_id array index (Nessus ID 208099)
11 months ago
A vulnerability was found in Linux Kernel up to 5.10.225/5.15.166/6.1.108/6.6.49/6.10.8 and classified as critical. This issue affects some unknown processing of the component AMD Display. The manipulation of the argument msg_id leads to improper validation of array index.
The identification of this vulnerability is CVE-2024-46814. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46807 | Linux Kernel up to 5.15.166/6.1.108/6.6.49/6.10.8 AMD GPU null pointer dereference (Nessus ID 208099)
11 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.15.166/6.1.108/6.6.49/6.10.8. This issue affects some unknown processing of the component AMD GPU. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-46807. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com