Aggregator
原始数据的防护之基:业务数据化阶段的数据安全建设(第九章)
1 year 3 months ago
CVE-2023-52667 | Linux Kernel up to 5.15.148/6.1.75/6.6.14/6.7.2 mlx5e kcalloc double free
1 year 3 months ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.15.148/6.1.75/6.6.14/6.7.2. Affected is the function kcalloc of the component mlx5e. The manipulation leads to double free.
This vulnerability is traded as CVE-2023-52667. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35953 | Linux Kernel up to 6.6.27/6.8.6 ivpu context_xa deadlock (d43e11d9c7fc/e60114111472/fd7726e75968)
1 year 3 months ago
A vulnerability was found in Linux Kernel up to 6.6.27/6.8.6. It has been rated as critical. This issue affects the function context_xa of the component ivpu. The manipulation leads to deadlock.
The identification of this vulnerability is CVE-2024-35953. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52851 | Linux Kernel up to 6.1.62/6.5.11/6.6.1 mlx5_mkey_cache_init use after free
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.1.62/6.5.11/6.6.1. Affected by this issue is the function mlx5_mkey_cache_init. The manipulation leads to use after free.
This vulnerability is handled as CVE-2023-52851. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52795 | Linux Kernel up to 6.1.63/6.5.12/6.6.2 vhost-vdpa vhost_vdpa_probe use after free
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.1.63/6.5.12/6.6.2. Affected by this issue is the function vhost_vdpa_probe of the component vhost-vdpa. The manipulation leads to use after free.
This vulnerability is handled as CVE-2023-52795. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52737 | Linux Kernel up to 6.1.12 kernel/sched/core.c fiemap_fill_next_extent deadlock (d8c594da79bc/519b7e13b5ae)
1 year 3 months ago
A vulnerability was found in Linux Kernel up to 6.1.12. It has been rated as critical. Affected by this issue is the function fiemap_fill_next_extent in the library arch/x86/lib/copy_user_64.S of the file kernel/sched/core.c. The manipulation leads to deadlock.
This vulnerability is handled as CVE-2023-52737. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47349 | Linux Kernel up to 5.12.17/5.13.2 mwifiex cfg80211_unregister_wdev deadlock (a3041d39d3c1/35af69c7c049/1f9482aa8d41)
1 year 3 months ago
A vulnerability has been found in Linux Kernel up to 5.12.17/5.13.2 and classified as problematic. This vulnerability affects the function cfg80211_unregister_wdev of the component mwifiex. The manipulation leads to deadlock.
This vulnerability was named CVE-2021-47349. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47198 | Linux Kernel up to 5.15.4 scsi lpfc_unreg_rpi use after free (dbebf865b323/79b20beccea3)
1 year 3 months ago
A vulnerability was found in Linux Kernel up to 5.15.4 and classified as problematic. Affected by this issue is the function lpfc_unreg_rpi of the component scsi. The manipulation leads to use after free.
This vulnerability is handled as CVE-2021-47198. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3645 | Essential Addons for Elementor Pro Plugin up to 5.8.11 on WordPress title_html_tag cross site scripting
1 year 3 months ago
A vulnerability was found in Essential Addons for Elementor Pro Plugin up to 5.8.11 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument title_html_tag leads to cross site scripting.
This vulnerability was named CVE-2024-3645. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-3733 | Essential Addons for Elementor Plugin up to 5.9.15 on WordPress information disclosure (ID 3075644)
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in Essential Addons for Elementor Plugin up to 5.9.15 on WordPress. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-3733. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-48649 | Linux Kernel up to 5.19.11 slab_common kmem_cache_destroy double free (c673c6ceac53/d71608a87736)
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.19.11. Affected is the function kmem_cache_destroy of the component slab_common. The manipulation leads to double free.
This vulnerability is traded as CVE-2022-48649. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26873 | Linux Kernel up to 6.7.10/6.8.1 hisi_sas deadlock (e022dd3b8753/85c98073ffcf/3c4f53b2c341 / Nessus ID 209785)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.7.10/6.8.1. Affected is an unknown function of the component hisi_sas. The manipulation leads to deadlock.
This vulnerability is traded as CVE-2024-26873. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
2025 SaaS Security Word of the Year: Adaptability | Grip
1 year 3 months ago
Discover why adaptability is the 2025 SaaS security word of the year. This is the year to address shadow SaaS, AI risks, and evolving cyber threats effectively!
The post 2025 SaaS Security Word of the Year: Adaptability | Grip appeared first on Security Boulevard.
Grip Security Blog
CVE-2017-1000028 | Oracle GlassFish Server Open Source Edition 4.1 HTTP GET Request path traversal (EDB-45196 / Nessus ID 110192)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Oracle GlassFish Server Open Source Edition 4.1. This affects an unknown part. The manipulation as part of HTTP GET Request leads to path traversal.
This vulnerability is uniquely identified as CVE-2017-1000028. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Company Revenue Lookup
1 year 3 months ago
Company Revenue Lookup
Dark Web Informer - Cyber Threat Intelligence
Threat Actors Exploit a Critical Ivanti RCE Bug, Again
1 year 3 months ago
New year, same story. Despite Ivanti's commitment to secure-by-design principles, threat actors — possibly the same ones as before — are exploiting its edge devices for the nth time.
Nate Nelson, Contributing Writer
China's UNC5337 Exploits a Critical Ivanti RCE Bug, Again
1 year 3 months ago
New year, same story. Despite Ivanti's commitment to secure-by-design principles, Chinese threat actors are exploiting its edge devices for the nth time.
Nate Nelson, Contributing Writer
CVE-2023-33245 | Mojang Minecraft up to 1.20 World Data symlink
1 year 3 months ago
A vulnerability was found in Mojang Minecraft up to 1.20. It has been declared as critical. This vulnerability affects unknown code of the component World Data Handler. The manipulation leads to symlink following.
This vulnerability was named CVE-2023-33245. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33656 | NanoMQ 0.17.2 message.c resource consumption (Issue 1164)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in NanoMQ 0.17.2. This issue affects some unknown processing of the file message.c. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2023-33656. Access to the local network is required for this attack. There is no exploit available.
vuldb.com