Aggregator
新型“幽灵通话”战术滥用 Zoom 与 Microsoft Teams 实施 C2 控制通信
4 months 1 week ago
安全客
CISA紧急命令:全美联邦机构须在周一前修复Exchange高危漏洞
4 months 1 week ago
安全客
ReVault 漏洞使攻击者可绕过戴尔笔记本电脑的 Windows 登录验证
4 months 1 week ago
安全客
CVE-2024-6248 | Wyze Cam 3 Authentication improper authentication
4 months 1 week ago
A vulnerability classified as critical was found in Wyze Cam 3. This vulnerability affects unknown code of the component Authentication Handler. The manipulation leads to improper authentication.
This vulnerability was named CVE-2024-6248. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6247 | Wyze Cam 3 Wi-Fi SSID os command injection
4 months 1 week ago
A vulnerability, which was classified as critical, has been found in Wyze Cam 3. This issue affects some unknown processing of the component Wi-Fi SSID Handler. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2024-6247. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6246 | Wyze Cam 3 Realtek Wi-Fi Driver heap-based overflow
4 months 1 week ago
A vulnerability, which was classified as critical, was found in Wyze Cam 3. Affected is an unknown function of the component Realtek Wi-Fi Driver. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-6246. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20339 | Cisco Firepower Threat Defense Software up to 7.3.1.2 TLS null pointer dereference (cisco-sa-ftd-tls-dos-QXYE5Ufy)
4 months 1 week ago
A vulnerability classified as critical was found in Cisco Firepower Threat Defense Software. Affected by this vulnerability is an unknown functionality of the component TLS. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-20339. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2019 | Ashlar-Vellum Cobalt VC6 File Parser heap-based overflow
4 months 1 week ago
A vulnerability has been found in Ashlar-Vellum Cobalt and classified as critical. Affected by this vulnerability is an unknown functionality of the component VC6 File Parser. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2025-2019. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2013 | Ashlar-Vellum Cobalt CO File Parser use after free
4 months 1 week ago
A vulnerability was found in Ashlar-Vellum Cobalt. It has been rated as critical. This issue affects some unknown processing of the component CO File Parser. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2025-2013. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2012 | Ashlar-Vellum Cobalt VS File Parser out-of-bounds
4 months 1 week ago
A vulnerability classified as critical has been found in Ashlar-Vellum Cobalt. Affected is an unknown function of the component VS File Parser. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2025-2012. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2018 | Ashlar-Vellum Cobalt VS File Parser type confusion
4 months 1 week ago
A vulnerability, which was classified as critical, has been found in Ashlar-Vellum Cobalt. Affected by this issue is some unknown functionality of the component VS File Parser. The manipulation leads to type confusion.
This vulnerability is handled as CVE-2025-2018. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2014 | Ashlar-Vellum Cobalt VS File Parser uninitialized pointer
4 months 1 week ago
A vulnerability was found in Ashlar-Vellum Cobalt and classified as critical. This issue affects some unknown processing of the component VS File Parser. The manipulation leads to uninitialized pointer.
The identification of this vulnerability is CVE-2025-2014. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-22963 | Sismics Teedy up to 1.11 /api/user/admin cross-site request forgery (EUVD-2025-3057)
4 months 1 week ago
A vulnerability was found in Sismics Teedy up to 1.11. It has been classified as problematic. This affects an unknown part of the file /api/user/admin. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-22963. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-6519 | QEMU SCSI use after free (Nessus ID 214975)
4 months 1 week ago
A vulnerability was found in QEMU. It has been classified as critical. This affects an unknown part of the component SCSI. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-6519. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2024-54021 | Fortinet FortiOS/FortiProxy HTTP Header response splitting (FG-IR-24-282 / EUVD-2024-52244)
4 months 1 week ago
A vulnerability was found in Fortinet FortiOS and FortiProxy and classified as critical. This issue affects some unknown processing of the component HTTP Header Handler. The manipulation leads to http response splitting.
The identification of this vulnerability is CVE-2024-54021. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45663 | IBM DB2/DB2 Connect Server 11.1/11.5 Query denial of service
4 months 1 week ago
A vulnerability has been found in IBM DB2 and DB2 Connect Server 11.1/11.5 and classified as problematic. This vulnerability affects unknown code of the component Query Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-45663. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Randall Munroe’s XKCD ‘Geologic Periods’
4 months 1 week ago
via the cosmic humor & dry-as-the-desert wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Geologic Periods’ appeared first on Security Boulevard.
Marc Handelman
趋势科技Apex One曝零日漏洞,已遭在野利用发起攻击
4 months 1 week ago
安全客
黑客利用嵌入恶意 JavaScript 的 SVG 文件在 Windows 系统执行恶意软件
4 months 1 week ago
安全客