Aggregator
CVE-2007-2659 | Bugada Andrea PHP Advanced Transfer Manager 1.30 index.php directory path traversal (EDB-3918 / XFDB-34255)
4 months ago
A vulnerability, which was classified as problematic, was found in Bugada Andrea PHP Advanced Transfer Manager 1.30. Affected is an unknown function of the file index.php. The manipulation of the argument directory leads to path traversal.
This vulnerability is traded as CVE-2007-2659. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2016-9878 | Oracle MySQL Enterprise Monitor up to 3.3.7.3306/3.4.5.4248/4.0.2.5168 EM Plugin path traversal (Nessus ID 111600 / ID 276356)
4 months ago
A vulnerability was found in Oracle MySQL Enterprise Monitor up to 3.3.7.3306/3.4.5.4248/4.0.2.5168. It has been declared as problematic. This vulnerability affects unknown code of the component EM Plugin. The manipulation leads to path traversal.
This vulnerability was named CVE-2016-9878. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-8740 | Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c input validation (EDB-40909 / Nessus ID 96037)
4 months ago
A vulnerability was found in Apache HTTP Server up to 2.4.23. It has been declared as problematic. This vulnerability affects unknown code of the file modules/http2/h2_stream.c of the component mod_http2. The manipulation leads to improper input validation.
This vulnerability was named CVE-2016-8740. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-7462 | Intellinet NFC-30ir IP Camera CGI Script path traversal (EDB-41829)
4 months ago
A vulnerability, which was classified as critical, was found in Intellinet NFC-30ir IP Camera. This affects an unknown part of the component CGI Script. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2017-7462. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Trinity
4 months ago
cohenido
CVE-2007-2658 | ID Automation Linear Barcode 1.6.0.5 ActiveX Control idautomationlinear6.dll denial of service (EDB-3917 / XFDB-34263)
4 months ago
A vulnerability, which was classified as critical, has been found in ID Automation Linear Barcode 1.6.0.5. This issue affects some unknown processing in the library idautomationlinear6.dll of the component ActiveX Control. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2007-2658. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
城市漫步指南:关西的夏日重现
4 months ago
島のどこにても、潮の音が聞こえる。その音を追えば、会える気がした。不管在岛的哪里,都能听见潮水的声音。感觉跟着这个声音,就能遇见她。——《夏日重现》夏日就要去海边啊。今年夏天去日本是我们一早就决定的。
CVE-2007-2667 | Db Soft Lab Vimp X 4.7.3 ActiveX Control vimpx.ocx LogFile memory corruption (EDB-3916 / XFDB-34260)
4 months ago
A vulnerability classified as very critical was found in Db Soft Lab Vimp X 4.7.3. Affected by this vulnerability is an unknown functionality of the file vimpx.ocx of the component ActiveX Control. The manipulation of the argument LogFile leads to memory corruption.
This vulnerability is known as CVE-2007-2667. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
AlpacaHack Round 3 (Crypto)
4 months ago
Name: AlpacaHack Round 3 (Crypto) (an AlpacaHack event.)
Date: Sept. 15, 2024, 3 a.m. — 15 Sept. 2024, 09:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://alpacahack.com/ctfs/round-3
Rating weight: 0
Event organizers: AlpacaHack
Date: Sept. 15, 2024, 3 a.m. — 15 Sept. 2024, 09:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://alpacahack.com/ctfs/round-3
Rating weight: 0
Event organizers: AlpacaHack
赏金15000美元的 RCE
4 months ago
黑客自 8 月以来频繁利用公开漏洞攻击 WhatsUp Gold
4 months ago
胡金鱼
CVE-2014-6760 | Harem Thief Dating 1.2.1 X.509 Certificate cryptographic issues (VU#582497)
4 months ago
A vulnerability, which was classified as critical, was found in Harem Thief Dating 1.2.1. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-6760. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
大模型的幻觉是不可避免地
4 months ago
随着大模型的日益普及,批判性地检查其固有的局限性也日益重要。幻觉是大模型最常见的问题之一,我们是否可能通过改进大模型去减少或阻止幻觉的产生?United We Care 的三名研究人员在预
CVE-2014-6759 | Downton Abbey Fan Portal 1 X.509 Certificate cryptographic issues (VU#582497)
4 months ago
A vulnerability, which was classified as critical, has been found in Downton Abbey Fan Portal 1. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-6759. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-8869 | TOTOLINK A720R 4.1.5 exportOvpn os command injection
4 months ago
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-8869. It is possible to launch the attack remotely. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2016-9878 | Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 Operations / Maintenance path traversal (Nessus ID 96220 / ID 276356)
4 months ago
A vulnerability has been found in Oracle Retail Assortment Planning 14.1.3/15.0.3/16.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Operations / Maintenance. The manipulation leads to path traversal.
This vulnerability is known as CVE-2016-9878. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 11
4 months ago
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Mythical Beasts and Where to Find Them: Mapping the Global Spyware Market and its Threats to National Security and Human Rights Dissecting Lumma Malware: Analyzing the Fake CAPTCHA and Obfuscation Techniques – Part 2 Predator Spyware […]
Pierluigi Paganini
CVE-2021-31755 | Tenda AC11 up to 02.03.01.104_CN POST Request /goform/setmac stack-based overflow
4 months ago
A vulnerability, which was classified as critical, was found in Tenda AC11 up to 02.03.01.104_CN. Affected is an unknown function of the file /goform/setmac of the component POST Request Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2021-31755. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-31207 | Microsoft Exchange Server 2013 CU23/2016 CU19/2016 CU20/2019 CU8/2019 CU9 ProxyShell unrestricted upload
4 months ago
A vulnerability classified as critical has been found in Microsoft Exchange Server 2013 CU23/2016 CU19/2016 CU20/2019 CU8/2019 CU9. Affected is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2021-31207. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com