Aggregator
USENIX NSDI ’24 – The Eternal Tussle: Exploring the Role of Centralization in IPFS
1 year ago
Authors/Presenters:Yiluo Wei, Dennis Trautwein, Yiannis Psaras, Ignacio Castro, Will Scott, Aravindh Raman, Gareth Tyson
Our sincere thanks to USENIX, and the Presenters & Authors for publishing their superb 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI '24) content, placing the organizations enduring commitment to Open Access front and center. Originating from the conference’s events situated at the Hyatt Regency Santa Clara; and via the organizations YouTube channel.
The post USENIX NSDI ’24 – The Eternal Tussle: Exploring the Role of Centralization in IPFS appeared first on Security Boulevard.
Marc Handelman
Special Operations Forces kunnen nu beschikken over eigen helikopters
1 year ago
Troepen die speciale operaties uitvoeren kunnen nu beschikken over ‘eigen’ helikopters. Die zijn ondergebracht bij het 300 Special Operations Squadron op Vliegbasis Gilze-Rijen. De eenheid van het Defensie Helikopter Commando is vandaag opgericht.
Mad Liberator
1 year ago
cohenido
CVE-2024-9411 | OFCMS 1.1.2 add.json add dict_value cross site scripting (IATECW)
1 year ago
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9411. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46276 | cute_headers cute_png 1.05 cute_png.h cp_chunk heap-based overflow
1 year ago
A vulnerability was found in cute_headers cute_png 1.05. It has been rated as critical. Affected by this issue is the function cp_chunk in the library cute_png.h. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-46276. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
因审核分歧 Raymond Hill 宣布 Ublock Origin lite 停止支持 Firefox
1 year ago
Mozilla 扩展商店 Firefox Add-ons Store 中的扩展需要接受人工审核。知名广告屏蔽扩展 Ublock Origin 系列的开发者 Raymond Hill 就 Ublock Origin lite(uBOL)与 Mozilla 审核团队之间发生了争执,他最终宣布 uBOL 停止支持 Firefox,Firefox 用户将需要从项目的 GitHub 页面直接下载该扩展。Ublock Origin 是基于 Manifest V2 的扩展,Google 正在淘汰 Manifest V2 强推限制更多的版本 Manifest V3,Raymond Hill 因此开发了基于 V3 的精简版本 uBOL。然而 Mozilla 的审核团队在审核 uBOL 时与开发者发生了冲突,认为该扩展存在混淆代码和收集私人数据。Raymond Hill 认为这种无意义的交流增加了他不想承担的负担,他宣布从扩展商店撤下扩展。原版的 Ublock Origin 仍然留在扩展商店。根据最后的邮件通信,Mozilla 审核团队为其错误道歉。
CVE-2024-44610 | Peak-System PCAN-Ethernet Gateway FD/PCAN-Ethernet Gateway command injection
1 year ago
A vulnerability was found in Peak-System PCAN-Ethernet Gateway FD and PCAN-Ethernet Gateway. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-44610. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44744 | Malwarebytes Premium Security 5.0.0.883 Binaries code injection
1 year ago
A vulnerability was found in Malwarebytes Premium Security 5.0.0.883. It has been classified as problematic. Affected is an unknown function of the component Binaries Handler. The manipulation leads to code injection.
This vulnerability is traded as CVE-2024-44744. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2023-7273 | Kiteworks OwnCloud up to 10.12.2 Header Authorization cross-site request forgery
1 year ago
A vulnerability was found in Kiteworks OwnCloud up to 10.12.2 and classified as problematic. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument Authorization leads to cross-site request forgery.
The identification of this vulnerability is CVE-2023-7273. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-46274 | cute_headers cute_png 1.05 cute_png.h cp_stored heap-based overflow
1 year ago
A vulnerability has been found in cute_headers cute_png 1.05 and classified as critical. This vulnerability affects the function cp_stored in the library cute_png.h. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-46274. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46267 | cute_headers cute_png 1.05 cute_png.h cp_block heap-based overflow
1 year ago
A vulnerability, which was classified as critical, was found in cute_headers cute_png 1.05. This affects the function cp_block in the library cute_png.h. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-46267. The attack needs to be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46264 | cute_headers cute_png 1.05 cute_png.h cp_find heap-based overflow
1 year ago
A vulnerability, which was classified as critical, has been found in cute_headers cute_png 1.05. Affected by this issue is the function cp_find in the library cute_png.h. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-46264. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46263 | cute_headers cute_png 1.05 cute_png.h cp_dynamic stack-based overflow
1 year ago
A vulnerability classified as critical was found in cute_headers cute_png 1.05. Affected by this vulnerability is the function cp_dynamic in the library cute_png.h. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-46263. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46261 | cute_headers cute_png 1.05 cute_png.h cp_make32 heap-based overflow
1 year ago
A vulnerability classified as critical has been found in cute_headers cute_png 1.05. Affected is the function cp_make32 in the library cute_png.h. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-46261. The attack needs to be approached within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46259 | cute_headers cute_png 1.05 cute_png.h cp_unfilter heap-based overflow
1 year ago
A vulnerability was found in cute_headers cute_png 1.05. It has been rated as critical. This issue affects the function cp_unfilter in the library cute_png.h. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-46259. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-46258 | cute_headers cute_png 1.05 cute_png.h cp_load_png_mem heap-based overflow
1 year ago
A vulnerability was found in cute_headers cute_png 1.05. It has been declared as critical. This vulnerability affects the function cp_load_png_mem in the library cute_png.h. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-46258. Access to the local network is required for this attack. Furthermore, there is an exploit available.
vuldb.com
I vertici aziendali non sono del tutto pronti alle nuove normative di sicurezza
1 year ago
CVE-2024-45967 | Pagekit 1.0.18 widget cross site scripting
1 year ago
A vulnerability was found in Pagekit 1.0.18. It has been classified as problematic. This affects an unknown part of the file index.php/admin/site/widget. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-45967. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Cybersecurity Awareness Month 2024: The Top Four Ways to Secure Our World
1 year ago
Cybersecurity Awareness Month 2024: The Top Four Ways to Secure Our WorldmadhavTue, 1