Aggregator
Medusa Blog
1 year ago
cohenido
Medusa Blog
1 year ago
cohenido
CVE-2013-0643 | Adobe Flash Player up to 11.6.602.168 Permission access control (APSB13-08 / Nessus ID 64916)
1 year ago
A vulnerability classified as critical was found in Adobe Flash Player up to 11.6.602.168. Affected by this vulnerability is an unknown functionality of the component Permission Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2013-0643. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-0648 | Adobe Flash Player up to 11.6.602.168 ExternalInterface in ActionScript memory corruption (APSB13-08 / Nessus ID 64916)
1 year ago
A vulnerability, which was classified as critical, has been found in Adobe Flash Player up to 11.6.602.168. Affected by this issue is some unknown functionality of the component ExternalInterface in ActionScript. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2013-0648. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0502 | Adobe Flash Player up to 11.3.300.270 resource management (APSB14-07 / Nessus ID 72606)
1 year ago
A vulnerability classified as very critical has been found in Adobe Flash Player up to 11.3.300.270. This affects an unknown part. The manipulation leads to improper resource management.
This vulnerability is uniquely identified as CVE-2014-0502. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8963 | Ivanti CSA up to 4.6 Patch 518 path traversal
1 year ago
A vulnerability classified as critical was found in Ivanti CSA up to 4.6 Patch 518. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-8963. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-0618 | Microsoft SQL Server 2012 SP4/2014 SP3/2016 SP2 Reporting Services deserialization (Advisory 156707)
1 year ago
A vulnerability was found in Microsoft SQL Server 2012 SP4/2014 SP3/2016 SP2. It has been rated as critical. This issue affects some unknown processing of the component Reporting Services. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2020-0618. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2020-14644 | Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Core Remote Code Execution
1 year ago
A vulnerability classified as very critical was found in Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0. Affected by this vulnerability is an unknown functionality of the component Core. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2020-14644. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-21445 | Oracle JDeveloper 12.2.1.3.0/12.2.1.4.0 ADF Faces deserialization
1 year ago
A vulnerability, which was classified as very critical, has been found in Oracle JDeveloper 12.2.1.3.0/12.2.1.4.0. Affected by this issue is some unknown functionality of the component ADF Faces. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2022-21445. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8190 | Ivanti CSA up to 4.6 Patch 518 os command injection
1 year ago
A vulnerability, which was classified as critical, was found in Ivanti CSA up to 4.6 Patch 518. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2024-8190. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6670 | Progress WhatsUp Gold HasErrors sql injection (ZDI-24-1185)
1 year ago
A vulnerability, which was classified as critical, has been found in Progress WhatsUp Gold. This issue affects the function HasErrors. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-6670. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Биткоин-лихорадка: от виртуального грабежа к реальным жертвам
1 year ago
Захват заложников, нападения и драки - новая реальность для криптоинвесторов.
CVE-2008-0943 | Aeries Student Information System 3.8.2.8 comments.asp Term sql injection (EDB-31275 / XFDB-40757)
1 year ago
A vulnerability was found in Aeries Student Information System 3.8.2.8 and classified as critical. Affected by this issue is some unknown functionality of the file comments.asp. The manipulation of the argument Term leads to sql injection.
This vulnerability is handled as CVE-2008-0943. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
严重的GiveWP漏洞(CVE-2024-8353)影响10万WordPress网站
1 year ago
安全客
Patchwork APT 的 Nexe 后门活动曝光
1 year ago
安全客
用户在一次复杂的钓鱼攻击中损失了价值3200万美元的spWETH
1 year ago
安全客
车牌信息成安全漏洞:起亚汽车远程控制风险揭示联网车辆网络安全问题
1 year ago
安全客
严重SQL注入漏洞影响TI WooCommerce Wishlist插件,超10万WordPress网站面临风险
1 year ago
安全客
解读SEC网络安全披露新规:8-K与10-K申报指南及企业应对策略
1 year ago
安全客