Aggregator
Sarcoma
2 months 2 weeks ago
You must login to view this content
cohenido
CitrixBleed 2 exploitation started mid-June — how to spot it
2 months 2 weeks ago
Kevin Beaumont
CVE-2025-32878 | COROS PACE 3 up to 3.0808.0 TLS Handshake certificate validation
2 months 2 weeks ago
A vulnerability has been found in COROS PACE 3 up to 3.0808.0 and classified as critical. This vulnerability affects unknown code of the component TLS Handshake Handler. The manipulation leads to improper certificate validation.
This vulnerability was named CVE-2025-32878. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-48705 | COROS up to 3.0808.0 BLE Message null pointer dereference
2 months 2 weeks ago
A vulnerability was found in COROS up to 3.0808.0 and classified as problematic. This issue affects some unknown processing of the component BLE Message Handler. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-48705. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-48706 | COROS PACE 3 up to 3.0808.0 BLE Message out-of-bounds (EUVD-2025-18751)
2 months 2 weeks ago
A vulnerability was found in COROS PACE 3 up to 3.0808.0. It has been classified as problematic. Affected is an unknown function of the component BLE Message Handler. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2025-48706. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-3227 | Mattermost up to 9.11.15/10.5.5/10.6.5/10.7.2/10.8.0 Playbook Run authorization (EUVD-2025-18758)
2 months 2 weeks ago
A vulnerability has been found in Mattermost up to 9.11.15/10.5.5/10.6.5/10.7.2/10.8.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Playbook Run Handler. The manipulation leads to incorrect authorization.
This vulnerability is known as CVE-2025-3227. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3228 | Mattermost up to 9.11.15/10.5.5/10.6.5/10.7.2/10.8.0 Playbook authorization (EUVD-2025-18757)
2 months 2 weeks ago
A vulnerability was found in Mattermost up to 9.11.15/10.5.5/10.6.5/10.7.2/10.8.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Playbook Handler. The manipulation leads to incorrect authorization.
This vulnerability is handled as CVE-2025-3228. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5479 | Sony XAV-AX8500 Bluetooth AVCTP Protocol heap-based overflow (EUVD-2025-18882)
2 months 2 weeks ago
A vulnerability classified as critical was found in Sony XAV-AX8500. Affected by this vulnerability is an unknown functionality of the component Bluetooth AVCTP Protocol Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2025-5479. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5478 | Sony XAV-AX8500 Bluetooth SDP Protocol integer overflow (EUVD-2025-18883)
2 months 2 weeks ago
A vulnerability, which was classified as very critical, has been found in Sony XAV-AX8500. Affected by this issue is some unknown functionality of the component Bluetooth SDP Protocol Handler. The manipulation leads to integer overflow.
This vulnerability is handled as CVE-2025-5478. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5477 | Sony XAV-AX8500 Bluetooth L2CAP Protocol heap-based overflow (EUVD-2025-18884)
2 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Sony XAV-AX8500. This affects an unknown part of the component Bluetooth L2CAP Protocol Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-5477. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5475 | Sony XAV-AX8500 Bluetooth Packet integer overflow (EUVD-2025-18885)
2 months 2 weeks ago
A vulnerability has been found in Sony XAV-AX8500 and classified as critical. This vulnerability affects unknown code of the component Bluetooth Packet Handler. The manipulation leads to integer overflow.
This vulnerability was named CVE-2025-5475. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5820 | Sony XAV-AX8500 Bluetooth ERTM Channel improper authentication (EUVD-2025-18880)
2 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Sony XAV-AX8500. Affected by this issue is some unknown functionality of the component Bluetooth ERTM Channel Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2025-5820. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5476 | Sony XAV-AX8500 Bluetooth improper authentication (EUVD-2025-18881)
2 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Sony XAV-AX8500. This affects an unknown part of the component Bluetooth. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2025-5476. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Вчера — борцы за идею, сегодня — шантажисты с Telegram-каналом
2 months 2 weeks ago
Эволюция хактивизма за год.
TikTok 计划九月推出一个美国专用版本
2 months 2 weeks ago
上个月美国总统特朗普第三次给予 TikTok 90 天宽限期,TikTok 必须在 9 月 17 日之前将其美国业务出售给美国财团,否则将会面临被禁。The Information 报道,如果出售给美国财团的交易获得批准,TikTok 已开发了一个美国专用版本,计划于 9 月 5 日推出。所有美国 TikTok 用户将被提示在 2026 年 3 月之前切换到新版应用,届时原版应用将停止运行。目前不清楚 TikTok 的美国版本与全球版本有什么区别。
Hackers 'Shellter' Various Stealers in Red-Team Tool to Evade Detection
2 months 2 weeks ago
Researchers have uncovered multiple campaigns spreading Lumma, Arechclient2, and Rhadamanthys malware by leveraging key features of the AV/EDR evasion framework.
Elizabeth Montalbano, Contributing Writer
CVE-2024-24778 | Apache StreamPipes up to 0.95.1 REST Interface privileges management
2 months 2 weeks ago
A vulnerability has been found in Apache StreamPipes up to 0.95.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component REST Interface. The manipulation leads to improper privilege management.
This vulnerability is known as CVE-2024-24778. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50699 | PHPGurukul Online DJ Booking Management System 2.0 view-user-queries.php cross site scripting (EUVD-2025-19041)
2 months 2 weeks ago
A vulnerability was found in PHPGurukul Online DJ Booking Management System 2.0. It has been classified as problematic. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-50699. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-0634 | Samsung rLottie 0.2 use after free (EUVD-2025-19505)
2 months 2 weeks ago
A vulnerability was found in Samsung rLottie 0.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to use after free.
This vulnerability is known as CVE-2025-0634. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com