Aggregator
Five Privilege Escalation Flaws Found in Ubuntu needrestart
6 days 8 hours ago
Five LPE flaws in Ubuntu’s needrestart utility enable attackers to gain root access in versions prior to 3.8
Sophos MDR blocks and tracks activity from probable Iranian state actor “MuddyWater”
6 days 8 hours ago
Sophos MDR has observed a new campaign that uses targeted phishing to entice the target to download a legitimate remote machine management tool to dump credentials. We believe with moderate confidence that this activity, which we track as STAC 1171, is related to an Iranian threat actor commonly referred to as MuddyWater or TA450. The […]
gallagherseanm
A Threat Actor is Allegedly Selling Data of Etudes Environnement
6 days 8 hours ago
A Threat Actor is Allegedly Selling Data of Etudes Environnement
Dark Web Informer
甲骨文云助手网页版
6 days 8 hours ago
一个基于 Oracle OCI SDK 开发的WEB端可视化甲骨文云助手,目前实现的功能有:支持批量添加多个租户配置、查询租户实例信息、根据多个CI
Microsoft Veeps Ignite Fire Under CrowdStrike
6 days 8 hours ago
BSODs begone! Redmond business leaders line up to say what’s new in Windows security.
The post Microsoft Veeps Ignite Fire Under CrowdStrike appeared first on Security Boulevard.
Richi Jennings
Anonymous Guys Targeted the Website of Kent
6 days 8 hours ago
Anonymous Guys Targeted the Website of Kent
Dark Web Informer
Leveling Up Fuzzing: Finding more vulnerabilities with AI
6 days 8 hours ago
Kimberly Samra
A Threat Actor Has Claimed to have Leaked the Data of CNfans
6 days 8 hours ago
A Threat Actor Has Claimed to have Leaked the Data of CNfans
Dark Web Informer
Microsoft confirms game audio issues on Windows 11 24H2 PCs
6 days 8 hours ago
Microsoft says a Windows 24H2 bug causes game audio to unexpectedly increase to full volume when using USB DAC sound systems. [...]
Sergiu Gatlan
Древние гены оживают: ученые создали новых мышей с помощью ДНК одноклеточных предков
6 days 9 hours ago
Одноклеточные организмы раскрывают секреты стволовых клеток.
New Ghost Tap attack abuses NFC mobile payments to steal money
6 days 9 hours ago
Cybercriminals have devised a novel method to cash out from stolen credit card details linked to mobile payment systems such as Apple Pay and Google Pay, dubbed 'Ghost Tap,' which relays NFC card data to money mules worldwide. [...]
Bill Toulas
CVE-2023-32203 | Horner Automation Cscape/Cscape EnvisionRV Project File Parser CScape_EnvisionRV memory corruption (icsa-23-143-04)
6 days 9 hours ago
A vulnerability was found in Horner Automation Cscape and Cscape EnvisionRV. It has been declared as critical. Affected by this vulnerability is the function CScape_EnvisionRV of the component Project File Parser. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2023-32203. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-32539 | Horner Automation Cscape/Cscape EnvisionRV Project File Parser CScape_EnvisionRV memory corruption (icsa-23-143-04)
6 days 9 hours ago
A vulnerability was found in Horner Automation Cscape and Cscape EnvisionRV. It has been rated as critical. Affected by this issue is the function CScape_EnvisionRV of the component Project File Parser. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2023-32539. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-31278 | Horner Automation Cscape/Cscape EnvisionRV Project File Parser memory corruption (icsa-23-143-04)
6 days 9 hours ago
A vulnerability classified as critical has been found in Horner Automation Cscape and Cscape EnvisionRV. This affects an unknown part of the component Project File Parser. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2023-31278. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23205 | Apple iOS/iPadOS log file
6 days 9 hours ago
A vulnerability, which was classified as problematic, was found in Apple iOS and iPadOS. This affects an unknown part. The manipulation leads to sensitive information in log files.
This vulnerability is uniquely identified as CVE-2024-23205. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23205 | Apple macOS log file
6 days 9 hours ago
A vulnerability has been found in Apple macOS and classified as problematic. This vulnerability affects unknown code. The manipulation leads to sensitive information in log files.
This vulnerability was named CVE-2024-23205. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-25394 | RT-Thread up to 5.0.2 utilities/ymodem/ry_sy.c sprintf buffer overflow (Issue 8291)
6 days 9 hours ago
A vulnerability, which was classified as critical, was found in RT-Thread up to 5.0.2. Affected is the function sprintf of the file utilities/ymodem/ry_sy.c. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2024-25394. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-3860 | Mozilla Firefox up to 124 JIT initialization
6 days 9 hours ago
A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 124. Affected by this issue is some unknown functionality of the component JIT Handler. The manipulation leads to improper initialization.
This vulnerability is handled as CVE-2024-3860. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-47252 | Insyde InsydeH2O SMM Communication out-of-bounds
6 days 9 hours ago
A vulnerability, which was classified as problematic, has been found in Insyde InsydeH2O up to 05.28.44/05.37.44/05.45.44/05.53.44/05.60.44. Affected by this issue is some unknown functionality of the component SMM Communication Handler. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2023-47252. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com