Aggregator
全球石油巨头因网络攻击损失超2.5亿元
1 year 4 months ago
公司现金流受影响
CVE-2016-4997 | Linux Kernel up to 3.14.72/4.4.13/4.6.2 compat_setsockopt access control (USN-3338-1 / EDB-40435)
1 year 4 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 3.14.72/4.4.13/4.6.2. This affects the function compat_setsockopt. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2016-4997. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-6305 | Freedirectoryscript Free Directory Script 1.1.1 init.php API_HOME_DIR code injection (EDB-7155 / XFDB-46699)
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Freedirectoryscript Free Directory Script 1.1.1. Affected by this issue is some unknown functionality of the file init.php. The manipulation of the argument API_HOME_DIR leads to code injection.
This vulnerability is handled as CVE-2008-6305. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6307 | E-topbiz Link Back Checker 1 improper authentication (EDB-7156 / XFDB-46697)
1 year 4 months ago
A vulnerability has been found in E-topbiz Link Back Checker 1 and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper authentication.
This vulnerability was named CVE-2008-6307. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6253 | Pluck-cms Pluck 4.5.3 pcltar.lib.php g_pcltar_lib_dir path traversal (EDB-7153 / XFDB-46676)
1 year 4 months ago
A vulnerability was found in Pluck-cms Pluck 4.5.3. It has been declared as critical. This vulnerability affects unknown code in the library data/inc/lib/pcltar.lib.php. The manipulation of the argument g_pcltar_lib_dir leads to path traversal.
This vulnerability was named CVE-2008-6253. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6308 | PunBB Private Messaging System up to 1.2.1 functions_navlinks.php pun_user[language] path traversal (EDB-7159 / XFDB-46718)
1 year 4 months ago
A vulnerability was found in PunBB Private Messaging System up to 1.2.1. It has been classified as problematic. Affected is an unknown function of the file functions_navlinks.php. The manipulation of the argument pun_user[language] leads to path traversal.
This vulnerability is traded as CVE-2008-6308. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6330 | Jaia Interactive MyTopix 1.2.3/1.3.0 index.php send sql injection (EDB-7160 / XFDB-46741)
1 year 4 months ago
A vulnerability classified as critical was found in Jaia Interactive MyTopix 1.2.3/1.3.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument send leads to sql injection.
This vulnerability was named CVE-2008-6330. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-5297 | Vitalwerks No-IP DUC up to 2.1.7 GetNextLine memory corruption (EDB-7151 / Nessus ID 35406)
1 year 4 months ago
A vulnerability classified as very critical has been found in Vitalwerks No-IP DUC up to 2.1.7. Affected is the function GetNextLine. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2008-5297. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
一头叫 Mary 的雌象学会了淋浴
1 year 4 months ago
柏林动物园一头叫 Mary 的雌象学会了使用软水管淋浴,而另一头羡慕万分的大象则试图阻止她使用水管。复杂工具使用和破坏行为在动物界都十分罕见。研究报告发表在《Current Biology》期刊上。圈养大象的平均年龄为 48 岁,而亚洲象 Mary 已经 54 岁,属于老年人了。它能灵活的使用软水管,用长鼻子卷起水管高过头顶,然后来回摇摆。它还会改变握住水管的方式,以方便喷洒身体的不同部位。研究人员用摄像机记录了它在一年时间里淋浴的过程。Mary 出生在野外,在不同动物园呆过,因此不太清楚它是自己发明还是模仿其它大象学会了淋浴。研究人员发现,另一头只有 12 岁的大象 Anchali 会在 Mary 洗澡时试图用鼻子卷起水管扭动以切断水流,阻止 Mary 洗澡。研究人员发现,Anchali 只针对 Mary,其它大象喷水不会去扭水管。
安全热点周报:大规模 PSAUX 勒索软件攻击瞄准 22,000 个 CyberPanel 实例
1 year 4 months ago
Пномпень против онлайн-аферистов: маленькая страна ведет большую битву
1 year 4 months ago
Полиция Камбоджи ликвидирует подпольные центры азартных игр.
从传统企业资产管理到CAASM
1 year 4 months ago
本文简要介绍了CAASM(网络资产攻击面管理)产生的背景,并对两个CAASM产品进行了介绍,最后展望了CAASM的未来发展。
派早报:Firefox 正式版发布二十年
1 year 4 months ago
你可能错过的新鲜事Firefox 正式版发布二十年2004 年 11 月 9 日,Firefox 发布 1.0 正式版,距今二十周年。该浏览器原名「凤凰」(Phoenix),意为诞生于已消亡 Ne
CVE-2015-6815 | Fabrice Bellard QEMU e1000 hw/net/e1000.c process_tx_desc infinite loop (USN-2745-1 / ID 168292)
1 year 4 months ago
A vulnerability was found in Fabrice Bellard QEMU. It has been classified as problematic. Affected is the function process_tx_desc of the file hw/net/e1000.c of the component e1000. The manipulation leads to infinite loop.
This vulnerability is traded as CVE-2015-6815. Access to the local network is required for this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Три года на виду у всех: как вредоносный пакет на PyPI собрал 37 000 скачиваний
1 year 4 months ago
Киберугроза проникла в код тысяч разработчиков и осталась необнаруженной.
The Top 9 Cyber Risk Management Trends in 2025 | Kovrr
1 year 4 months ago
Articles related to cyber risk quantification, cyber risk management, and cyber resilience.
The post The Top 9 Cyber Risk Management Trends in 2025 | Kovrr appeared first on Security Boulevard.
Cyber Risk Quantification
密码学中的加解密
1 year 4 months ago
密码学中常见的加解密
CVE-2015-8367 | Libraw up to 0.17.0 phase_one_correct initialization (ID 134573 / ID 169361)
1 year 4 months ago
A vulnerability was found in Libraw up to 0.17.0. It has been rated as critical. Affected by this issue is the function phase_one_correct. The manipulation leads to improper initialization.
This vulnerability is handled as CVE-2015-8367. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11074 | itsourcecode Tailoring Management System 1.0 /incadd.php inccat/desc/date/amount sql injection
1 year 4 months ago
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file /incadd.php. The manipulation of the argument inccat/desc/date/amount leads to sql injection.
This vulnerability was named CVE-2024-11074. The attack can be initiated remotely. Furthermore, there is an exploit available.
The initial researcher advisory only mentions the parameter "inccat" to be affected. But it must be assumed "desc", "date", and "amount" are affected as well.
vuldb.com