Aggregator
.NET内网实战:不安全的系统令牌特权
1 year ago
.NET 一款支持天蝎的免杀WebShell
1 year ago
CVE-2007-4313 | Php Blue Dragon CMS 3.0 activecontent.php vsDragonRootPath file inclusion (EDB-4276 / XFDB-35945)
1 year ago
A vulnerability classified as critical has been found in Php Blue Dragon CMS 3.0. This affects an unknown part of the file activecontent.php. The manipulation of the argument vsDragonRootPath leads to file inclusion.
This vulnerability is uniquely identified as CVE-2007-4313. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Spider-Man (Neversoft) decompilation project Progress Checkpoint - September 2024
1 year ago
CVE-2024-40914 | Linux Kernel up to 6.9.5 huge_memory unpoison_memory reference count (Nessus ID 207738)
1 year ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.9.5. Affected is the function unpoison_memory of the component huge_memory. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2024-40914. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36015 | Linux Kernel up to 6.9 ppdev register_device return value (fbf740aeb86a / Nessus ID 207738)
1 year ago
A vulnerability was found in Linux Kernel up to 6.9. It has been classified as problematic. This affects the function register_device of the component ppdev. The manipulation leads to unchecked return value.
This vulnerability is uniquely identified as CVE-2024-36015. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38547 | Linux Kernel up to 6.9.2 ssh_css load_video_binaries null pointer dereference (Nessus ID 207738)
1 year ago
A vulnerability has been found in Linux Kernel up to 6.9.2 and classified as critical. This vulnerability affects the function load_video_binaries of the component ssh_css. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-38547. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38381 | Linux Kernel up to 6.9.3 nfc nci_rx_work uninitialized resource (Nessus ID 207738)
1 year ago
A vulnerability has been found in Linux Kernel up to 6.9.3 and classified as critical. This vulnerability affects the function nci_rx_work of the component nfc. The manipulation leads to uninitialized resource.
This vulnerability was named CVE-2024-38381. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38560 | Linux Kernel up to 6.9.2 scsi memdup_user_nul buffer overflow (Nessus ID 207738)
1 year ago
A vulnerability has been found in Linux Kernel up to 6.9.2 and classified as critical. This vulnerability affects the function memdup_user_nul of the component scsi. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2024-38560. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39277 | Linux Kernel up to 5.15.160/6.1.92/6.6.32/6.9.3 topology.h cpumask_of_node array index (Nessus ID 207738)
1 year ago
A vulnerability was found in Linux Kernel up to 5.15.160/6.1.92/6.6.32/6.9.3. It has been declared as critical. Affected by this vulnerability is the function cpumask_of_node in the library /arch/x86/include/asm/topology.h. The manipulation leads to improper validation of array index.
This vulnerability is known as CVE-2024-39277. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-7090 | VCCCD MyVCCCD 1.4.14 X.509 Certificate cryptographic issues (VU#582497)
1 year ago
A vulnerability was found in VCCCD MyVCCCD 1.4.14. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-7090. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
AI Pulse: What's new in AI regulations?
1 year ago
Fall is in the air and frameworks for mitigating AI risk are dropping like leaves onto policymakers’ desks. From California’s SB 1047 bill and NIST’s model-testing deal with OpenAI and Anthropic to REAIM’s blueprint for military AI governance, AI regulation is proving to be a hot and complicated topic.
AI Team
What Are Hackers Searching for in SolarWinds Serv-U (CVE-2024-28995)?
1 year ago
Discover how GreyNoise’s honeypots are monitoring exploit attempts on the SolarWinds Serv-U vulnerability (CVE-2024-28995). Gain insights into the specific files attackers target and how real-time data helps security teams focus on true threats. Read our full blog for detailed analysis.
MDR in Action: Preventing The More_eggs Backdoor From Hatching
1 year ago
Trend Micro MDR (Managed Detection and Response) team promptly mitigated a more_eggs infection. Using Vision One, MDR illustrated how Custom Filters/Models and Security Playbook can be used to automate the response to more_eggs and similar threats.
Ryan Soliven
Israel army hacked the communication network of the Beirut Airport control tower
1 year ago
Israel army hacked the communication network of the Beirut Airport control tower Pierluigi Paga
CVE-2014-7089 | Appsgeyser COMPETITION INFORMATION 0.1 X.509 Certificate cryptographic issues (VU#582497)
1 year ago
A vulnerability was found in Appsgeyser COMPETITION INFORMATION 0.1. It has been declared as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-7089. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2014-7088 | JDM Lifestyle 6.4 X.509 Certificate cryptographic issues (VU#582497)
1 year ago
A vulnerability was found in JDM Lifestyle 6.4. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7088. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
以明文形式存储数亿个密码,Meta 被罚 1 亿美元
1 year ago
error code: 521
Kill
1 year ago
cohenido