Aggregator
Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #308 – What Are Those?
11 months 2 weeks ago
via the respected Software Engineering expertise of Mikkel Noe-Nygaard and the lauded Software Engineering / Enterprise Agile Coaching work of Luxshan Ratnaravi at Comic Agilé!
The post Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #308 – What Are Those? appeared first on Security Boulevard.
Marc Handelman
Google Joins Forces with GASA and DNS RF to Tackle Online Scams at Scale
11 months 2 weeks ago
Google on Wednesday announced a new partnership with the Global Anti-Scam Alliance (GASA) and DNS Research Federation (DNS RF) to combat online scams.
The initiative, which has been codenamed the Global Signal Exchange (GSE), is designed to create real-time insights into scams, fraud, and other forms of cybercrime pooling together threat signals from different data sources in order to create
The Hacker News
CVE-2004-1792 | Yatsoft Switch Off up to 2.3 swnet.dll infinite loop (EDB-23508 / XFDB-14123)
11 months 2 weeks ago
A vulnerability was found in Yatsoft Switch Off up to 2.3. It has been classified as problematic. Affected is an unknown function in the library swnet.dll. The manipulation leads to infinite loop.
This vulnerability is traded as CVE-2004-1792. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
我国工业互联网安全领域首批国家标准发布
11 months 2 weeks ago
打破物理隔离!多个政府机密系统遭APT组织攻破
11 months 2 weeks ago
摆渡攻击显威力
Microsoft fixes Word bug that deleted documents when saving
11 months 2 weeks ago
Microsoft has fixed a known issue that was causing Word to delete some Windows users' documents instead of saving them. [...]
Sergiu Gatlan
Взлом Dr.Web: компания подверглась масштабной кибератаке
11 months 2 weeks ago
Компания усиливает меры безопасности после атаки.
CVE-2024-38538 | Linux Kernel up to 6.1.92/6.6.32/6.8.11/6.9.2 xmit uninitialized variable (Nessus ID 208425)
11 months 2 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.92/6.6.32/6.8.11/6.9.2. Affected is an unknown function of the component xmit. The manipulation leads to use of uninitialized variable.
This vulnerability is traded as CVE-2024-38538. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-9199 | PoDoFo 0.9.6 pdftranslator.cpp setSource PDF File null pointer dereference (ID 40 / Nessus ID 208427)
11 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in PoDoFo 0.9.6. This issue affects the function PoDoFo::Impose::PdfTranslator::setSource of the file pdftranslator.cpp. The manipulation as part of PDF File leads to null pointer dereference.
The identification of this vulnerability is CVE-2019-9199. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2019-10723 | PoDoFo 0.9.6 PdfPagesTreeCache.cpp PdfPagesTreeCache resource management (ID 46 / Nessus ID 208427)
11 months 2 weeks ago
A vulnerability was found in PoDoFo 0.9.6. It has been classified as problematic. This affects the function PdfPagesTreeCache of the file doc/PdfPagesTreeCache.cpp. The manipulation leads to improper resource management.
This vulnerability is uniquely identified as CVE-2019-10723. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2023-52752 | Linux Kernel up to 6.1.63/6.5.12/6.6.2 /proc/fs/cifs/DebugData cifs_debug_data_proc_show use after free (Nessus ID 208425)
11 months 2 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.63/6.5.12/6.6.2. Affected by this vulnerability is the function cifs_debug_data_proc_show of the file /proc/fs/cifs/DebugData. The manipulation leads to use after free.
This vulnerability is known as CVE-2023-52752. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52916 | Linux Kernel up to 6.5 denial of service (c281355068bc / Nessus ID 208425)
11 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.5. Affected by this issue is some unknown functionality. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2023-52916. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-6841 | PoDoFo 0.9.5 graphicsstack.h ~TGraphicsStackElement null pointer dereference (Nessus ID 208427)
11 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in PoDoFo 0.9.5. Affected by this issue is the function GraphicsStack::TGraphicsStackElement::~TGraphicsStackElement of the file graphicsstack.h. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2017-6841. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-6849 | PoDoFo 0.9.4 PdfColor.cpp ~PdfColorGray null pointer dereference (Nessus ID 208427)
11 months 2 weeks ago
A vulnerability classified as problematic was found in PoDoFo 0.9.4. This vulnerability affects the function PoDoFo::PdfColorGray::~PdfColorGray of the file PdfColor.cpp. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2017-6849. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-5535 | OpenSSL up to 3.3.1 Client Protocol SSL_select_next_proto client/client_len memory corruption (Nessus ID 208438)
11 months 2 weeks ago
A vulnerability was found in OpenSSL up to 3.3.1. It has been declared as critical. This vulnerability affects the function SSL_select_next_proto of the component Client Protocol Handler. The manipulation of the argument client/client_len leads to memory corruption.
This vulnerability was named CVE-2024-5535. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43484 | Microsoft .NET/.NET Framework/Visual Studio algorithmic complexity (Nessus ID 208439)
11 months 2 weeks ago
A vulnerability was found in Microsoft .NET, .NET Framework and Visual Studio. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to inefficient algorithmic complexity.
This vulnerability is known as CVE-2024-43484. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43485 | Microsoft .NET/Visual Studio algorithmic complexity (Nessus ID 208439)
11 months 2 weeks ago
A vulnerability was found in Microsoft .NET and Visual Studio. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to inefficient algorithmic complexity.
This vulnerability is handled as CVE-2024-43485. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-46292 | OWASP ModSecurity 3.0.12 Input name denial of service
11 months 2 weeks ago
A vulnerability was found in OWASP ModSecurity 3.0.12. It has been classified as problematic. Affected is an unknown function of the component Input Handler. The manipulation of the argument name leads to denial of service.
This vulnerability is traded as CVE-2024-46292. The attack needs to be approached within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46304 | libcoap up to 4.3.5-rc2 src/coap_block.c coap_handle_request_put_block denial of service
11 months 2 weeks ago
A vulnerability was found in libcoap up to 4.3.5-rc2 and classified as problematic. This issue affects the function coap_handle_request_put_block of the file src/coap_block.c. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2024-46304. The attack may be initiated remotely. There is no exploit available.
vuldb.com