Aggregator
Seven Malicious Go Packages Found Deploying Malware on Linux and macOS Systems
1 year 3 months ago
Cybersecurity researchers are alerting of an ongoing malicious campaign targeting the Go ecosystem with typosquatted modules that are designed to deploy loader malware on Linux and Apple macOS systems.
"The threat actor has published at least seven packages impersonating widely used Go libraries, including one (github[.]com/shallowmulti/hypert) that appears to target financial-sector developers
The Hacker News
Хактивизм на службе разведки: как государства маскируют кибератаки
1 year 3 months ago
Исследователи распутывают связи между хактивистскими группами.
CVE-2019-20170 | GPAC 0.8.0/0.9.0-development-20191109 odf/ipmpx_code.c GF_IPMPX_AUTH_Delete release of reference (Issue 1328 / Nessus ID 222863)
1 year 3 months ago
A vulnerability has been found in GPAC 0.8.0/0.9.0-development-20191109 and classified as problematic. Affected by this vulnerability is the function GF_IPMPX_AUTH_Delete of the file odf/ipmpx_code.c. The manipulation leads to release of reference.
This vulnerability is known as CVE-2019-20170. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2019-20812 | Linux Kernel up to 5.4.6 net/packet/af_packet.c prb_calc_retire_blk_tmo Packet resource consumption (Nessus ID 222862)
1 year 3 months ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.4.6. Affected is the function prb_calc_retire_blk_tmo of the file net/packet/af_packet.c. The manipulation as part of Packet leads to resource consumption.
This vulnerability is traded as CVE-2019-20812. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-19037 | Linux Kernel up to 5.3.12 fs/ext4/namei.c ext4_empty_dir null pointer dereference (DLA 2114-1 / Nessus ID 222864)
1 year 3 months ago
A vulnerability was found in Linux Kernel up to 5.3.12 and classified as problematic. Affected by this issue is the function ext4_empty_dir of the file fs/ext4/namei.c. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2019-19037. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2019-20352 | Netwide Assembler 2.15rc0 ASM File asm/preproc.c set_text_free out-of-bounds (Nessus ID 222865)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Netwide Assembler 2.15rc0. Affected by this issue is the function set_text_free of the file asm/preproc.c of the component ASM File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2019-20352. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2019-17014 | Mozilla Firefox up to 70.x Image inclusion of functionality from untrusted control sphere (MFSA 2019-36 / Nessus ID 222867)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 70.x. This issue affects some unknown processing of the component Image Handler. The manipulation leads to inclusion of functionality from untrusted control sphere.
The identification of this vulnerability is CVE-2019-17014. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-19080 | Linux Kernel up to 5.3.3 main.c nfp_flower_spawn_phy_reprs resource consumption (Nessus ID 222868)
1 year 3 months ago
A vulnerability was found in Linux Kernel up to 5.3.3. It has been declared as problematic. Affected by this vulnerability is the function nfp_flower_spawn_phy_reprs of the file drivers/net/ethernet/netronome/nfp/flower/main.c. The manipulation leads to resource consumption.
This vulnerability is known as CVE-2019-19080. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1931 | Mozilla Firefox up to 135 WebTransport use after free (Nessus ID 222870)
1 year 3 months ago
A vulnerability was found in Mozilla Firefox up to 135 and classified as critical. Affected by this issue is some unknown functionality of the component WebTransport. The manipulation leads to use after free.
This vulnerability is handled as CVE-2025-1931. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1937 | Mozilla Thunderbird up to 135 memory corruption (Nessus ID 222870)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird up to 135. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2025-1937. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1932 | Mozilla Firefox up to 135 txNodeSorter out-of-bounds (Nessus ID 222870)
1 year 3 months ago
A vulnerability was found in Mozilla Firefox up to 135. It has been classified as problematic. This affects an unknown part of the component txNodeSorter. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-1932. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1930 | Mozilla Firefox up to 135 on Windows AudioIPC use after free (Nessus ID 222870)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 135 on Windows. This affects an unknown part of the component AudioIPC. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2025-1930. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43097 | Google Android 12/12L/13/14/15 SkRegion.cpp resizeToAtLeast out-of-bounds write (Nessus ID 222870)
1 year 3 months ago
A vulnerability was found in Google Android 12/12L/13/14/15. It has been rated as critical. Affected by this issue is the function resizeToAtLeast of the file SkRegion.cpp. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2024-43097. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-1937 | Mozilla Firefox up to 135 memory corruption (Nessus ID 222870)
1 year 3 months ago
A vulnerability classified as critical was found in Mozilla Firefox up to 135. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2025-1937. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CCF Talk活动预告:大模型时代的软件工程:那些变的和不变的
1 year 3 months ago
3月10日(周一)晚上7:30开始,可扫码预约线上参加
CCF Talk活动预告:大模型时代的软件工程:那些变的和不变的
1 year 3 months ago
3月10日(周一)晚上7:30开始,可扫码预约线上参加
CCF Talk活动预告:大模型时代的软件工程:那些变的和不变的
1 year 3 months ago
3月10日(周一)晚上7:30开始,可扫码预约线上参加
CCF Talk活动预告:大模型时代的软件工程:那些变的和不变的
1 year 3 months ago
3月10日(周一)晚上7:30开始,可扫码预约线上参加
CCF Talk活动预告:大模型时代的软件工程:那些变的和不变的
1 year 3 months ago
3月10日(周一)晚上7:30开始,可扫码预约线上参加