Aggregator
CVE-2023-0668 | Wireshark up to 3.6.13/4.0.5 IEEE C37.118 Synchrophasor Dissector denial of service (wnpa-sec-2023-19 / Nessus ID 207910)
11 months 4 weeks ago
A vulnerability was found in Wireshark up to 3.6.13/4.0.5. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IEEE C37.118 Synchrophasor Dissector. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2023-0668. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8118 | Grafana up to 10.3.9/10.4.8/11.0.4/11.1.5/11.2.0 API Endpoint improper isolation or compartmentalization (Nessus ID 208027)
11 months 4 weeks ago
A vulnerability has been found in Grafana up to 10.3.9/10.4.8/11.0.4/11.1.5/11.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component API Endpoint. The manipulation leads to improper isolation or compartmentalization.
This vulnerability is known as CVE-2024-8118. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Из царства грибов в мир технологий: вешенки управляют роботами
11 months 4 weeks ago
Еще один неожиданный союз биологии и механики.
How to download ida free on the new website without creating an account?
11 months 4 weeks ago
CVE-2016-4210 | Adobe Acrobat Reader up to 11.0.16/15.006.30174/15.016.20045 memory corruption (APSB16-26 / Nessus ID 92036)
11 months 4 weeks ago
A vulnerability has been found in Adobe Acrobat Reader up to 11.0.16/15.006.30174/15.016.20045 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2016-4210. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-0666 | Wireshark up to 4.0.5 RTPS Dissector denial of service (wnpa-sec-2023-18 / Nessus ID 207910)
11 months 4 weeks ago
A vulnerability was found in Wireshark up to 4.0.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component RTPS Dissector. The manipulation leads to denial of service.
This vulnerability is known as CVE-2023-0666. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-4344 | Wireshark up to 3.6.9/4.0.1 Kafka Protocol Dissector memory leak (Nessus ID 207910)
11 months 4 weeks ago
A vulnerability was found in Wireshark up to 3.6.9/4.0.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Kafka Protocol Dissector. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2022-4344. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-4345 | Wireshark up to 3.6.9/4.0.1 BPv6/OpenFlow/Kafka infinite loop (Nessus ID 207910)
11 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Wireshark up to 3.6.9/4.0.1. This issue affects some unknown processing of the component BPv6/OpenFlow/Kafka. The manipulation leads to infinite loop.
The identification of this vulnerability is CVE-2022-4345. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-3190 | Wireshark up to 3.4.15/3.6.7 F5 Ethernet Trailer Protocol Dissector denial of service (Issue 18307 / Nessus ID 207910)
11 months 4 weeks ago
A vulnerability has been found in Wireshark up to 3.4.15/3.6.7 and classified as problematic. This vulnerability affects unknown code of the component F5 Ethernet Trailer Protocol Dissector. The manipulation leads to denial of service.
This vulnerability was named CVE-2022-3190. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Randall Munroe’s XKCD ‘UK Coal’
11 months 4 weeks ago
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘UK Coal’ appeared first on Security Boulevard.
Marc Handelman
CVE-2024-47803 | Jenkins prior 2.462.x/2.477.x Form Submission secretTextarea information exposure
11 months 4 weeks ago
A vulnerability was found in Jenkins. It has been rated as problematic. This issue affects some unknown processing of the component Form Submission Handler. The manipulation of the argument secretTextarea leads to information exposure through error message.
The identification of this vulnerability is CVE-2024-47803. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47807 | Jenkins OpenId Connect Authentication Plugin up to 4.354.v321ce67a_1de8 improper authentication
11 months 4 weeks ago
A vulnerability was found in Jenkins OpenId Connect Authentication Plugin up to 4.354.v321ce67a_1de8. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to improper authentication.
This vulnerability was named CVE-2024-47807. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-47806 | Jenkins OpenId Connect Authentication Plugin up to 4.354.v321ce67a_1de8 improper authentication
11 months 4 weeks ago
A vulnerability was found in Jenkins OpenId Connect Authentication Plugin up to 4.354.v321ce67a_1de8. It has been classified as critical. This affects an unknown part. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2024-47806. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
Fake Trading Apps Target Victims Globally via Apple App Store and Google Play
11 months 4 weeks ago
A large-scale fraud campaign leveraged fake trading apps published on the Apple App Store and Google Play Store, as well as phishing sites, to defraud victims, per findings from Group-IB.
The campaign is part of a consumer investment fraud scheme that's also widely known as pig butchering, in which prospective victims are lured into making investments in cryptocurrency or other financial
The Hacker News
CVE-2016-4209 | Adobe Acrobat Reader up to 11.0.16/15.006.30174/15.016.20045 memory corruption (APSB16-26 / Nessus ID 92036)
11 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Adobe Acrobat Reader up to 11.0.16/15.006.30174/15.016.20045. Affected is an unknown function. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2016-4209. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Microsoft Office 2024 now available for Windows and macOS users
11 months 4 weeks ago
Microsoft has released Office 2024 for small businesses and consumers who want a standalone version without a Microsoft 365 subscription. [...]
Sergiu Gatlan
CVE-2022-36803 | Atlassian Jira Align prior 10.109.2 MasterUserEdit API permission
11 months 4 weeks ago
A vulnerability was found in Atlassian Jira Align. It has been rated as critical. Affected by this issue is some unknown functionality of the component MasterUserEdit API. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2022-36803. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-43781 | Atlassian Bitbucket Server and Data Center Environment Variable username command injection
11 months 4 weeks ago
A vulnerability was found in Atlassian Bitbucket Server and Data Center. It has been classified as critical. Affected is an unknown function of the component Environment Variable Handler. The manipulation of the argument username leads to command injection.
This vulnerability is traded as CVE-2022-43781. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-43782 | Atlassian Crowd up to 4.4.3/5.0.2 REST API improper authentication
11 months 4 weeks ago
A vulnerability was found in Atlassian Crowd up to 4.4.3/5.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component REST API. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2022-43782. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com