Aggregator
Android app三种常见抓包场景及案例分析
3 months 3 weeks ago
看雪论坛作者ID:scllqk
CVE-2021-1789 | Apple macOS up to 11.1 WebKit type confusion (HT212147)
3 months 3 weeks ago
A vulnerability was found in Apple macOS up to 11.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to type confusion.
This vulnerability is handled as CVE-2021-1789. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-1789 | Apple iOS/iPadOS WebKit type confusion
3 months 3 weeks ago
A vulnerability classified as critical was found in Apple iOS and iPadOS. Affected by this vulnerability is an unknown functionality of the component WebKit. The manipulation leads to type confusion.
This vulnerability is known as CVE-2021-1789. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-1789 | Apple watchOS WebKit type confusion
3 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Apple watchOS. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to type confusion.
This vulnerability is handled as CVE-2021-1789. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-1789 | Apple tvOS WebKit type confusion
3 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Apple tvOS. This affects an unknown part of the component WebKit. The manipulation leads to type confusion.
This vulnerability is uniquely identified as CVE-2021-1789. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | VMware Spring Cloud Gateway up to 3.0.6/3.1.0 Actuator Endpoint code injection (EDB-50799)
3 months 3 weeks ago
A vulnerability was found in VMware Spring Cloud Gateway up to 3.0.6/3.1.0. It has been classified as very critical. This affects an unknown part of the component Actuator Endpoint. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2022-22947. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Network Exposure Function NEF code injection (EDB-50799)
3 months 3 weeks ago
A vulnerability, which was classified as very critical, has been found in Oracle Communications Cloud Native Core Network Exposure Function 22.1.0. Affected by this issue is some unknown functionality of the component NEF. The manipulation leads to code injection.
This vulnerability is handled as CVE-2022-22947. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-1388 | F5 BIG-IP up to 13.1.4/14.1.4.5/15.1.5.0/16.1.2.1 iControl REST Authentication /mgmt/tm/util/bash missing authentication (K23605346 / EDB-50932)
3 months 3 weeks ago
A vulnerability, which was classified as very critical, has been found in F5 BIG-IP up to 13.1.4/14.1.4.5/15.1.5.0/16.1.2.1. Affected by this issue is some unknown functionality of the file /mgmt/tm/util/bash of the component iControl REST Authentication. The manipulation leads to missing authentication.
This vulnerability is handled as CVE-2022-1388. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-30525 | ZyXEL USG FLEX 50 CGI Program os command injection (EDB-50946)
3 months 3 weeks ago
A vulnerability classified as critical has been found in ZyXEL USG FLEX 100, USG FLEX 200, USG FLEX 500, USG FLEX 700, USG FLEX 20 and USG FLEX 50. Affected is an unknown function of the component CGI Program Handler. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2022-30525. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Binding Support Function BSF code injection (EDB-50799)
3 months 3 weeks ago
A vulnerability, which was classified as very critical, was found in Oracle Communications Cloud Native Core Binding Support Function 22.1.3. Affected is an unknown function of the component BSF. The manipulation leads to code injection.
This vulnerability is traded as CVE-2022-22947. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Console 22.2.0 CNC Console code injection (EDB-50799)
3 months 3 weeks ago
A vulnerability has been found in Oracle Communications Cloud Native Core Console 22.2.0 and classified as very critical. Affected by this vulnerability is an unknown functionality of the component CNC Console. The manipulation leads to code injection.
This vulnerability is known as CVE-2022-22947. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Network Repository Function NRF code injection (EDB-50799)
3 months 3 weeks ago
A vulnerability was found in Oracle Communications Cloud Native Core Network Repository Function 22.1.2/22.2.0 and classified as very critical. Affected by this issue is some unknown functionality of the component NRF. The manipulation leads to code injection.
This vulnerability is handled as CVE-2022-22947. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP code injection (EDB-50799)
3 months 3 weeks ago
A vulnerability was found in Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1. It has been classified as very critical. This affects an unknown part of the component SEPP. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2022-22947. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Network Slice Selection Function NSSF code injection (EDB-50799)
3 months 3 weeks ago
A vulnerability, which was classified as very critical, was found in Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0/1.8.0. This affects an unknown part of the component NSSF. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2022-22947. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
签约!威努特与华为正式达成合作
3 months 3 weeks ago
强强联手,共建繁荣生态,达成互利共赢。
CVE-2022-38580 | Zalando Skipper 0.13.236 server-side request forgery (EDB-51111)
3 months 3 weeks ago
A vulnerability was found in Zalando Skipper 0.13.236. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2022-38580. The attack needs to be approached within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-3325 | LMS LAN Management System up to 1.6.9 lib/language.php _LIB_DIR file inclusion (EDB-4086 / XFDB-34959)
3 months 3 weeks ago
A vulnerability was found in LMS LAN Management System up to 1.6.9 and classified as critical. This issue affects some unknown processing in the library lib/language.php. The manipulation of the argument _LIB_DIR leads to file inclusion.
The identification of this vulnerability is CVE-2007-3325. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
前苹果设计师 Jony Ive 证实为 OpenAI 开发硬件;长城汽车加入华为鸿蒙生态;X 平台推原创剧 | 极客早知道
3 months 3 weeks ago
前苹果设计总监 Jony Ive 确认正与 OpenAI 开发一款新设备,iPhone 元老级人物加盟 9 月 22 日消息,今年 4 月曾有消息称,OpenAI 首席执行官山姆・阿尔特曼(Sam A
CVE-2014-6918 | Bikers Underground 4.5.10 X.509 Certificate cryptographic issues (VU#582497)
3 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Bikers Underground 4.5.10. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-6918. The attack can only be done within the local network. There is no exploit available.
vuldb.com