Aggregator
野蛮fuzz:快照与代码覆盖率
1 year 4 months ago
看雪论坛作者ID:pureGavin
第三届ADConf 议程全揭晓 | 11月13日,期待与您相会!
1 year 4 months ago
轻松全掌握,大会精彩议程。
Wi-Fi测试套件漏洞入侵商用路由器 背后原因剖析
1 year 4 months ago
Wi-Fi危机 商用路由器面临安全风险
CVE-2024-51132 | HAPI FHIR up to 6.3.x Request xml external entity reference
1 year 4 months ago
A vulnerability classified as problematic was found in HAPI FHIR up to 6.3.x. This vulnerability affects unknown code of the component Request Handler. The manipulation leads to xml external entity reference.
This vulnerability was named CVE-2024-51132. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51362 | LSC Smart Connect Indoor IP Camera up to 7.6.32 RTSP Protocol information disclosure
1 year 4 months ago
A vulnerability classified as problematic has been found in LSC Smart Connect Indoor IP Camera up to 7.6.32. This affects an unknown part of the component RTSP Protocol Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-51362. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50099 | Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4 Virtual Address simulate_ldr_literal Privilege Escalation
1 year 4 months ago
A vulnerability was found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4. It has been rated as problematic. Affected by this issue is the function simulate_ldr_literal of the component Virtual Address Handler. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-50099. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50128 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 Netlink Attribute lib/nlattr.c wwan_rtnl_policy out-of-bounds
1 year 4 months ago
A vulnerability was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. It has been declared as problematic. Affected by this vulnerability is the function wwan_rtnl_policy in the library lib/nlattr.c of the component Netlink Attribute Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-50128. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50136 | Linux Kernel up to 6.1.114/6.6.58/6.11.5 mlx5 eswitch_vport_event information disclosure
1 year 4 months ago
A vulnerability was found in Linux Kernel up to 6.1.114/6.6.58/6.11.5. It has been classified as problematic. Affected is the function eswitch_vport_event of the component mlx5. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-50136. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50097 | Linux Kernel up to 6.6.56/6.11.3/6.12-rc1 fec_ptp_init initialization (7745e14f4c03/3192e8d4a1ef/6be063071a45)
1 year 4 months ago
A vulnerability was found in Linux Kernel up to 6.6.56/6.11.3/6.12-rc1 and classified as problematic. This issue affects the function fec_ptp_init. The manipulation leads to improper initialization.
The identification of this vulnerability is CVE-2024-50097. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
AI安全赛道 | 真正的技术考验,大模型安全问题如何破?(文末抽奖)
1 year 4 months ago
@AI安全赛道参赛人
APT-C-08(蔓灵花)组织:多元攻击载体大揭秘
1 year 4 months ago
本文将详细披露蔓灵花组织近一年使用过的载体文件以及相应的变化过程
CVE-2024-50135 | Linux Kernel up to 6.6.58/6.11.5 nvme-pci drivers/pci/msi/api.c nvme_dev_disable race condition (4ed32cc0939b/b33e49a5f254/26bc0a81f64c)
1 year 4 months ago
A vulnerability has been found in Linux Kernel up to 6.6.58/6.11.5 and classified as problematic. This vulnerability affects the function nvme_dev_disable of the file drivers/pci/msi/api.c of the component nvme-pci. The manipulation leads to race condition.
This vulnerability was named CVE-2024-50135. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50134 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 vboxvideo vbva_mouse_pointer_shape allocation of resources
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. This affects the function vbva_mouse_pointer_shape of the component vboxvideo. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-50134. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
“整合”全能网络安全平台?全是营销套路
1 year 4 months ago
首次利用大模型发现内存安全零日漏洞 (附大模型挖洞经验)
1 year 4 months ago
大模型擅长发现已知漏洞变种
CVE-2024-50130 | Linux Kernel up to 6.6.58/6.11.5 netfilter __nf_unregister_net_hook use after free (f41bd93b3e05/d0d7939543a1/1230fe7ad397)
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.58/6.11.5. Affected by this issue is the function __nf_unregister_net_hook of the component netfilter. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-50130. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50127 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 taprio_change use after free
1 year 4 months ago
A vulnerability classified as critical was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. Affected by this vulnerability is the function taprio_change. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-50127. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50125 | Linux Kernel up to 6.1.114/6.6.58/6.11.5 Bluetooth sco_sock_timeout use after free
1 year 4 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.114/6.6.58/6.11.5. Affected is the function sco_sock_timeout of the component Bluetooth. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-50125. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50124 | Linux Kernel up to 6.1.114/6.6.58/6.11.5 Bluetooth iso_sock_timeout use after free
1 year 4 months ago
A vulnerability was found in Linux Kernel up to 6.1.114/6.6.58/6.11.5. It has been rated as critical. This issue affects the function iso_sock_timeout of the component Bluetooth. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-50124. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com