Aggregator
黑客自 8 月以来频繁利用公开漏洞攻击 WhatsUp Gold
1 year 6 months ago
胡金鱼
CVE-2014-6760 | Harem Thief Dating 1.2.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Harem Thief Dating 1.2.1. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-6760. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
大模型的幻觉是不可避免地
1 year 6 months ago
随着大模型的日益普及,批判性地检查其固有的局限性也日益重要。幻觉是大模型最常见的问题之一,我们是否可能通过改进大模型去减少或阻止幻觉的产生?United We Care 的三名研究人员在预
CVE-2014-6759 | Downton Abbey Fan Portal 1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in Downton Abbey Fan Portal 1. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-6759. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-8869 | TOTOLINK A720R 4.1.5 exportOvpn os command injection
1 year 6 months ago
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-8869. It is possible to launch the attack remotely. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2016-9878 | Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Operations / Maintenance path traversal (Nessus ID 96220 / ID 276356)
1 year 6 months ago
A vulnerability has been found in Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Operations / Maintenance. The manipulation leads to path traversal.
This vulnerability is known as CVE-2016-9878. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 11
1 year 6 months ago
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Mythical Beasts and Where to Find Them: Mapping the Global Spyware Market and its Threats to National Security and Human Rights Dissecting Lumma Malware: Analyzing the Fake CAPTCHA and Obfuscation Techniques – Part 2 Predator Spyware […]
Pierluigi Paganini
CVE-2021-31755 | Tenda AC11 up to 02.03.01.104_CN POST Request /goform/setmac stack-based overflow
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Tenda AC11 up to 02.03.01.104_CN. Affected is an unknown function of the file /goform/setmac of the component POST Request Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2021-31755. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-31207 | Microsoft Exchange Server 2013 CU23/2016 CU19/2016 CU20/2019 CU8/2019 CU9 ProxyShell unrestricted upload
1 year 6 months ago
A vulnerability classified as critical has been found in Microsoft Exchange Server 2013 CU23/2016 CU19/2016 CU20/2019 CU8/2019 CU9. Affected is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2021-31207. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-31956 | Microsoft Windows up to Server 2019 NTFS integer underflow
1 year 6 months ago
A vulnerability was found in Microsoft Windows and classified as very critical. This issue affects some unknown processing of the component NTFS. The manipulation leads to integer underflow.
The identification of this vulnerability is CVE-2021-31956. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-35211 | SolarWinds Serv-U Managed File Transfer up to 15.2.3 HF1 on Windows buffer overflow
1 year 6 months ago
A vulnerability was found in SolarWinds Serv-U Managed File Transfer up to 15.2.3 HF1 on Windows and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2021-35211. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-6758 | Mgsasia Qin Story 1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability classified as critical was found in Mgsasia Qin Story 1. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-6758. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2002-1426 | HP ProCurve Switch 4000M C.07.23 SNMP Service memory corruption (EDB-21657 / XFDB-9708)
1 year 6 months ago
A vulnerability was found in HP ProCurve Switch 4000M C.07.23. It has been rated as very critical. Affected by this issue is some unknown functionality of the component SNMP Service. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2002-1426. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
哈勃发现一对超大质量黑洞
1 year 6 months ago
当星系发生碰撞与合并时,位于其中心的超大质量黑洞也最终会合并为一个更大的黑洞。几乎每个星系的中心都拥有一个超大质量黑洞。最近哈勃太空望远镜与钱德勒 X 射线天文台在一对正在合并的星系中心发现了一对相互环绕的超大质量黑洞。这两个黑洞相距约 300 光年,预计约在 1 亿年后合并。这是迄今为止在可见光与 X 射线波段中观测到的最近距离的双超大质量黑洞。它们位于编号为 MCG-03-34-64 的星系对中心,距地球约 8 亿光年。由于黑洞吸收了周围大量的气体及尘埃,吸积作用使得该星系核心亮度大增,成为活跃星系核(AGN)。虽然过去已发现数十对双黑洞,但它们之间的距离比这次发现的要远得多。
Haiku 释出 R1/Beta5
1 year 6 months ago
开源 BeOS 操作系统 Haiku 释出了 Haiku R1 的第五个 Beta 版本。主要变化包括:改进 UI 颜色管理、改进暗模式配色、改进 Tracker、VPN 连接支持 TUN/TAP、改进 TCP 吞吐量、性能优化、BSD 文件系统 UFS2 的只读支持、新 FAT 文件系统驱动、改进硬件支持、改进 POSIX 兼容性、改进性能等等。Haiku 是 BeOS 的精神继承者,BeOS 操作系统在 2001 年被 Palm 收购后停止开发,Haiku 项目在这之后不久正式启动,2002 年发布了首个版本,2012 年发布 Haiku R1 Alpha 4.1,六年后发布了 Haiku R1/beta1。Haiku 专注于简洁用户友好的设计,有着较低的系统需求,最低硬件需求是 Intel Pentium II/AMD Athlon CPU 或更高版本,384 MB 内存,800x600 分辨率显示屏,3GB 硬盘存储空间。
CVE-2014-6757 | Allqoranvideos Koran - AlqoranVideos 1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability classified as critical has been found in Allqoranvideos Koran - AlqoranVideos 1. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-6757. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
Games Box - 1,439,354 breached accounts
1 year 6 months ago
Here's an overview of the various breaches that have been consolidated into this Have I BeenPwned.
CVE-2007-2660 | CJG EXPLORER PRO up to 3.3 lib/pcltrace.lib.php g_pcltar_lib_dir file inclusion (EDB-3915 / XFDB-34273)
1 year 6 months ago
A vulnerability has been found in CJG EXPLORER PRO up to 3.3 and classified as critical. Affected by this vulnerability is an unknown functionality in the library lib/pcltrace.lib.php. The manipulation of the argument g_pcltar_lib_dir leads to file inclusion.
This vulnerability is known as CVE-2007-2660. The attack can be launched remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
vuldb.com
CVE-2014-6756 | biais Reddit Aww 1.2.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability was found in biais Reddit Aww 1.2.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-6756. The attack can only be done within the local network. There is no exploit available.
vuldb.com