Aggregator
G.O.S.S.I.P 阅读推荐 2024-10-16 LLM帮你理解安全补丁
1 year 5 months ago
用LLM来理解安全补丁,尽早取代安全分析人员(手动狗头)
CVE-2014-7734 | onesolutionapps Reds Anytime Bail 1.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 5 months ago
A vulnerability classified as critical was found in onesolutionapps Reds Anytime Bail 1.1. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-7734. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
Lynx
1 year 5 months ago
cohenido
Lynx
1 year 5 months ago
cohenido
CVE-2024-8404 | PaperCut NG/MF up to 23.0.8 on Windows Web Print link following (Nessus ID 209141)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in PaperCut NG and MF up to 23.0.8 on Windows. Affected by this issue is some unknown functionality of the component Web Print. The manipulation leads to link following.
This vulnerability is handled as CVE-2024-8404. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8405 | PaperCut NG/MF up to 23.0.8 on Windows Web Print command injection (Nessus ID 209141)
1 year 5 months ago
A vulnerability classified as critical was found in PaperCut NG and MF up to 23.0.8 on Windows. Affected by this vulnerability is an unknown functionality of the component Web Print. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-8405. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3037 | PaperCut NG/MF up to 23.0.8 on Windows Web Print link following (Nessus ID 209141)
1 year 5 months ago
A vulnerability was found in PaperCut NG and MF up to 23.0.8 on Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Print. The manipulation leads to link following.
This vulnerability is handled as CVE-2024-3037. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-4712 | PaperCut NG/MF up to 23.0.8 on Windows Web Print link following (Nessus ID 209141)
1 year 5 months ago
A vulnerability classified as critical has been found in PaperCut NG and MF up to 23.0.8 on Windows. This affects an unknown part of the component Web Print. The manipulation leads to link following.
This vulnerability is uniquely identified as CVE-2024-4712. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47009 | Ivanti Avalanche up to 6.4.4 path traversal (Nessus ID 209148)
1 year 5 months ago
A vulnerability was found in Ivanti Avalanche up to 6.4.4. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-47009. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47010 | Ivanti Avalanche up to 6.4.4 path traversal (Nessus ID 209148)
1 year 5 months ago
A vulnerability classified as critical has been found in Ivanti Avalanche up to 6.4.4. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-47010. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47011 | Ivanti Avalanche up to 6.4.4 path traversal (Nessus ID 209148)
1 year 5 months ago
A vulnerability classified as critical was found in Ivanti Avalanche up to 6.4.4. This vulnerability affects unknown code. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-47011. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47008 | Ivanti Avalanche up to 6.4.4 server-side request forgery (Nessus ID 209148)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in Ivanti Avalanche up to 6.4.4. Affected is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2024-47008. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47007 | Ivanti Avalanche up to 6.4.4 WLAvalancheService.exe null pointer dereference (Nessus ID 209148)
1 year 5 months ago
A vulnerability was found in Ivanti Avalanche up to 6.4.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file WLAvalancheService.exe. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-47007. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22899 | Vinchin Backup & Recovery 7.2 syncNtpTime Privilege Escalation
1 year 5 months ago
A vulnerability classified as critical has been found in Vinchin Backup & Recovery 7.2. Affected is the function syncNtpTime. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2024-22899. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-25407 | SteVe 3.6.0 Transaction ID denial of service (Issue 1296)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in SteVe 3.6.0. Affected by this issue is some unknown functionality of the component Transaction ID Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-25407. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-24337 | Koha Library Management System up to 23.05.05 Budget/Patrons Member csv injection
1 year 5 months ago
A vulnerability was found in Koha Library Management System up to 23.05.05. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Budget/Patrons Member. The manipulation leads to csv injection.
This vulnerability is known as CVE-2024-24337. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-25119 | TYPO3 Install Tool information disclosure (GHSA-h47m-3f78-qp9g)
1 year 5 months ago
A vulnerability was found in TYPO3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Install Tool. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-25119. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-25118 | TYPO3 Backend Forms information disclosure (GHSA-38r2-5695-334w)
1 year 5 months ago
A vulnerability classified as problematic has been found in TYPO3. This affects an unknown part of the component Backend Forms. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-25118. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Log4j威胁阴影未散,超13%运行实例仍存安全隐患; APT34最新攻击手法揭秘:瞄准微软Exchange服务器 | 牛览
1 year 5 months ago
新闻速览•第八届“强网杯”全国网络安全挑战赛正式启动•我国科研人员成功用量子计算破解RSA加密算法•美国背景调查巨头因重大数据泄露事件陷入破产困境•《精灵宝可梦》开发商遭遇大规模数据泄露,近1TB敏感