Aggregator
46% of financial institutions had a data breach in the past 24 months
1 year 3 months ago
As the financial industry is the most targeted sector for data breaches in 2024, it’s now more important than ever to strengthen the industry moving into 2025, according to SailPoint. Financial institutions face growing cyber threats In 2024, roughly 65% of financial organizations worldwide reported experiencing a ransomware attack, compared to 64% in 2023 and 34% in 2021. 46% of financial companies recorded indicated they had a breach in just the last 24 months. 80% … More →
The post 46% of financial institutions had a data breach in the past 24 months appeared first on Help Net Security.
Help Net Security
CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List
1 year 3 months ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical secur
CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List
1 year 3 months ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The vulnerability, tracked as CVE-2024-12356 (CVSS score: 9.8), is a command injection flaw that
The Hacker News
CVE-2000-0573 | University of Washington wu-ftpd 2.6.0 site exec Command lreply format string (EDB-201 / Nessus ID 10452)
1 year 3 months ago
A vulnerability was found in University of Washington wu-ftpd 2.6.0. It has been rated as very critical. Affected by this issue is the function lreply of the component site exec Command. The manipulation leads to format string.
This vulnerability is handled as CVE-2000-0573. The attack may be launched remotely. Furthermore, there is an exploit available. This vulnerability has a historic impact due to its background and reception.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-0767 | Adobe Flash Player up to 10.1.102.64 cross site scripting (RHSA-2012:0144 / EDB-18572)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Adobe Flash Player. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2012-0767. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-2423 | Oracle Java up to 7 Update 17 Hotspot memory corruption (EDB-24976 / Nessus ID 69742)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Oracle Java up to 7 Update 17. This issue affects some unknown processing of the component Hotspot. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2013-2423. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-6287 | Rejetto HTTP File Server up to 2.x parserLib.pas findMacroMarker code injection (ID 128243 / VU#251276)
1 year 3 months ago
A vulnerability was found in Rejetto HTTP File Server up to 2.x and classified as critical. This issue affects the function findMacroMarker in the library parserLib.pas. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2014-6287. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-4912 | PHP DocWriter up to 0.3 script file inclusion (EDB-2373 / XFDB-28989)
1 year 3 months ago
A vulnerability classified as critical was found in PHP DocWriter up to 0.3. This vulnerability affects unknown code. The manipulation of the argument script leads to file inclusion.
This vulnerability was named CVE-2006-4912. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-4946 | CMSDevelopment Business Card Web Builder up to 0.99 root_path file inclusion (EDB-2399 / XFDB-29039)
1 year 3 months ago
A vulnerability classified as critical has been found in CMSDevelopment Business Card Web Builder up to 0.99. Affected is an unknown function. The manipulation of the argument root_path leads to file inclusion.
This vulnerability is traded as CVE-2006-4946. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-4960 | Blue Dragon Php Blue Dragon up to 2.9.1 Error Message index.php Reflected cross site scripting (EDB-2402 / XFDB-29066)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Blue Dragon Php Blue Dragon up to 2.9.1. Affected is an unknown function of the file index.php of the component Error Message Handler. The manipulation leads to basic cross site scripting (Reflected).
This vulnerability is traded as CVE-2006-4960. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-4961 | Blue Dragon Php Blue Dragon up to 2.9.1 getmoduleconfig sql injection (EDB-2402 / XFDB-29051)
1 year 3 months ago
A vulnerability has been found in Blue Dragon Php Blue Dragon up to 2.9.1 and classified as critical. Affected by this vulnerability is the function getmoduleconfig. The manipulation leads to sql injection.
This vulnerability is known as CVE-2006-4961. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-4962 | Blue Dragon Php Blue Dragon up to 2.9.1 pbd_engine.php phpExt path traversal (EDB-2402 / XFDB-29067)
1 year 3 months ago
A vulnerability was found in Blue Dragon Php Blue Dragon up to 2.9.1 and classified as critical. Affected by this issue is some unknown functionality of the file pbd_engine.php. The manipulation of the argument phpExt leads to path traversal.
This vulnerability is handled as CVE-2006-4962. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-4452 | Web3king Web3news 0.95 class.security.php PHPSECURITYADMIN_PATH file inclusion (EDB-2269 / XFDB-28618)
1 year 3 months ago
A vulnerability classified as critical has been found in Web3king Web3news 0.95. This affects an unknown part of the file class.security.php. The manipulation of the argument PHPSECURITYADMIN_PATH leads to file inclusion.
This vulnerability is uniquely identified as CVE-2006-4452. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-4867 | GNUTurk Gnuturk Portal System up to 2g mods.php go sql injection (EDB-2378 / BID-20069)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in GNUTurk Gnuturk Portal System up to 2g. Affected by this issue is some unknown functionality of the file mods.php. The manipulation of the argument go leads to sql injection.
This vulnerability is handled as CVE-2006-4867. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-4898 | guanxiCRM Guanxicrm Business Solution up to 0.9.1 appconf[rootpath] file inclusion (EDB-2381 / XFDB-28994)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in guanxiCRM Guanxicrm Business Solution up to 0.9.1. This affects an unknown part. The manipulation of the argument appconf[rootpath] leads to file inclusion.
This vulnerability is uniquely identified as CVE-2006-4898. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Dfir tools, automation AI
1 year 3 months ago
Hi, I am trying to find the best setup for dfir analysis. I played around with: Sofelk, Ka
CVE-2014-1759 | Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption (MS14-020 / Nessus ID 73417)
1 year 3 months ago
A vulnerability classified as critical has been found in Microsoft Publisher 2003/2007. Affected is an unknown function in the library pubconv.dll of the component Publisher File Handler. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2014-1759. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-2783 | Microsoft Internet Explorer 7/8/9/10/11 Certificate access control (MS14-037 / Nessus ID 76406)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Microsoft Internet Explorer 7/8/9/10/11. Affected is an unknown function of the component Certificate Handler. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2014-2783. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-2809 | Microsoft Internet Explorer up to 11 memory corruption (MS14-037 / Nessus ID 76406)
1 year 3 months ago
A vulnerability was found in Microsoft Internet Explorer up to 11 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2014-2809. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com