Aggregator
三菱不打算参与本田日产的合并
1 year 3 months ago
登录 注册
三菱不打算参与本田日产的合并
1 year 3 months ago
因为规模较小担心合并后经营自主性下降,三菱汽车表示不打算参与本田日产的合并。本田和日产是在去年 12 月宣布全面启动经营合并磋商,计划 2026 年 8 月成立把两家车企纳入旗下的控股公司。与日产组成企业联盟的三菱汽车公司将在 2025 年 1 月底前后决定是否加入。若三家车企成功合并,那么合计销量将超过 800 万辆,位居全球第三。三菱汽车认为,在汽车行业主战场转移到纯电动汽车和软件领域的背景下,三家公司的合并效果并不明朗。
Self-changing Data Type - CVE-2024-40676 漏洞分析
1 year 3 months ago
今年 10 月份的时候,Android 安全公告用 CVE-2024-40676 的编号公布了一个很奇怪的 patch。AccountManagerService checkKeyIntent() 负
CVE-2024-55919 | Sympa SSO improper authentication (Nessus ID 214418)
1 year 3 months ago
A vulnerability was found in Sympa. It has been declared as critical. This vulnerability affects unknown code of the component SSO. The manipulation leads to improper authentication.
This vulnerability was named CVE-2024-55919. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-46401 | KWHotel 0.47 csv injection
1 year 3 months ago
A vulnerability was found in KWHotel 0.47. It has been classified as problematic. This affects an unknown part. The manipulation leads to csv injection.
This vulnerability is uniquely identified as CVE-2023-46401. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-50665 | GPAC 2.4 MP4Box drm_sample.c isom_cenc_get_sai_by_saiz_saio memory corruption (Issue 2987)
1 year 3 months ago
A vulnerability was found in GPAC 2.4 and classified as critical. Affected by this issue is the function isom_cenc_get_sai_by_saiz_saio of the file src/isomedia/drm_sample.c of the component MP4Box. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2024-50665. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2023-46400 | KWHotel 0.47 Add Guest csv injection
1 year 3 months ago
A vulnerability has been found in KWHotel 0.47 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Add Guest. The manipulation leads to csv injection.
This vulnerability is known as CVE-2023-46400. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-55195 | OpenImageIO 3.1.0.0dev /imagebuf.cpp denial of service (Issue 4553)
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in OpenImageIO 3.1.0.0dev. Affected is an unknown function of the file /imagebuf.cpp. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-55195. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-50664 | GPAC 2.4 MP4Box isomedia/sample_descs.c gf_isom_new_mpha_description heap-based overflow (Issue 2988)
1 year 3 months ago
A vulnerability classified as critical was found in GPAC 2.4. This vulnerability affects the function gf_isom_new_mpha_description of the file isomedia/sample_descs.c of the component MP4Box. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-50664. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-57556 | nbubna store up to 2.14.2 store.deep.js cross site scripting (Issue 127)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in nbubna store up to 2.14.2. This issue affects some unknown processing of the file store.deep.js. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-57556. The attack may be initiated remotely. There is no exploit available.
vuldb.com
豆包大模型 1.5 不走「捷径」,火山引擎要造「长坡厚雪」
1 year 3 months ago
豆包大模型 8 个月迭代数次,给火山引擎带来了什么?
CVE-2024-57386 | Wallos 2.41.0 Profile Picture cross site scripting
1 year 3 months ago
A vulnerability classified as problematic has been found in Wallos 2.41.0. This affects an unknown part of the component Profile Picture Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-57386. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-53588 | iTop VPN 16.0 DLL vpn6 uncontrolled search path
1 year 3 months ago
A vulnerability was found in iTop VPN 16.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file \ProgramData\iTop VPN\Downloader\vpn6 of the component DLL Handler. The manipulation leads to uncontrolled search path.
This vulnerability is handled as CVE-2024-53588. The attack needs to be approached locally. There is no exploit available.
vuldb.com
JVN: mySCADA製myPROにおける複数のOSコマンドインジェクションの脆弱性
1 year 3 months ago
mySCADAが提供するmyPROには、複数のOSコマンドインジェクションの脆弱性が存在します。
Breach Roundup: Researchers Find Flaws in Palo Alto Firewalls
1 year 3 months ago
Also: US Prosecutors Charge Suspected North Korean IT Worker Collaborators
This week, researchers spied Palo Alto firewall flaws, a North Korean IT worker conspiracy, ChatGPT as DDoS vector. Chinese hackers targeted a VPN maker, a fake PyPi package and a Russian threat actor shifted tactics. BreachForums admin faces prison and scammers used the release of Ross Ulbricht.
This week, researchers spied Palo Alto firewall flaws, a North Korean IT worker conspiracy, ChatGPT as DDoS vector. Chinese hackers targeted a VPN maker, a fake PyPi package and a Russian threat actor shifted tactics. BreachForums admin faces prison and scammers used the release of Ross Ulbricht.
CISA Warns of Flaws in Aircraft Collision Avoidance Systems
1 year 3 months ago
Hackers Unlikely to Exploit Flaws in the Wild
Security researchers found an unpatchable flaw in the system that prevents commercial aircraft from crashing into each other, the U.S. federal government said in a Tuesday advisory that called the likelihood of its exploitation "unlikely" outside of a laboratory setting.
Security researchers found an unpatchable flaw in the system that prevents commercial aircraft from crashing into each other, the U.S. federal government said in a Tuesday advisory that called the likelihood of its exploitation "unlikely" outside of a laboratory setting.
Lawsuit Claims LinkedIn Used Private Messages to Train AI
1 year 3 months ago
California User's Class Action Suit Says LinkedIn Violated Contract, Privacy Regs
A LinkedIn user has sued the company for flouting privacy requirements by allowing third-party companies to access user data - including Premium users' private messages - to train their artificial intelligence models. A LinkedIn spokesperson called the lawsuit "false claims with no merit."
A LinkedIn user has sued the company for flouting privacy requirements by allowing third-party companies to access user data - including Premium users' private messages - to train their artificial intelligence models. A LinkedIn spokesperson called the lawsuit "false claims with no merit."
JVN: HMS Networks製Ewon Flexy 202における重要情報の平文送信の脆弱性
1 year 3 months ago
HMS Networksが提供するEwon Flexy 202には、重要情報の平文送信の脆弱性が存在します。
当你想来一次新年大扫除,这里或许有些经验可供参考
1 year 3 months ago
元旦已过,又是一年春节要来到。作为第一次不回家过的年,这个年对我而言意义非凡,因此,在考虑自己写挥春、准备除夕夜和伴侣及朋友的聚餐同时,也在规划着如何打扫自己的居所,希望在各个方面都以干净整洁的姿态,