Aggregator
【安全圈】新型 Vo1d 恶意软件曝光,超130万台安卓电视设备已中招
4 months ago
RansomHub
4 months ago
cohenido
Vo1d malware infected 1.3 Million Android-based TV Boxes in 197 countries
4 months ago
Researchers uncovered an Android malware, dubbed Vo1d, that has already infected nearly 1.3 million Android devices in 197 countries. Doctor Web researchers uncovered a malware, tracked as Vo1d, that infected nearly 1.3 million Android-based TV boxes belonging to users in 197 countries. The malicious code acts as a backdoor and allows attackers to download and install […]
Pierluigi Paganini
x64dbg入门实战 | 本周更新:插件编写
4 months ago
掌握x64dbg,从基础到高级调试与自动化
GitLab 修复一个9.9分漏洞,允许未经授权执行管道作业
4 months ago
该漏洞的严重性来自于其远程利用的可能性、无需用户交互以及低权限要求,可让攻击者以停止操作作业的所有者身份执行环境停止操作。
浅探内联挂钩的水有多深
4 months ago
看雪论坛作者ID:Ratin
SDC 安全训练营——8小时解锁新安全技能
4 months ago
培训时间:10月22日09:00-18:00(峰会前一天)
CVE-2021-27104 | Accellion FTA up to 9.12.370 Admin Endpoint os command injection
4 months ago
A vulnerability has been found in Accellion FTA up to 9.12.370 and classified as critical. This vulnerability affects unknown code of the component Admin Endpoint. The manipulation leads to os command injection.
This vulnerability was named CVE-2021-27104. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-28310 | Microsoft Windows up to Server 2019 Win32k out-of-bounds write
4 months ago
A vulnerability was found in Microsoft Windows up to Server 2019. It has been rated as critical. Affected by this issue is some unknown functionality of the component Win32k. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2021-28310. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-28663 | ARM Mali GPU Kernel Driver use after free
4 months ago
A vulnerability was found in ARM Mali GPU Kernel Driver. It has been classified as critical. Affected is an unknown function. The manipulation leads to use after free.
This vulnerability is traded as CVE-2021-28663. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-28664 | ARM Mali GPU Kernel Driver access control
4 months ago
A vulnerability classified as critical was found in ARM Mali GPU Kernel Driver. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2021-28664. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-27562 | ARM Trusted Firmware-M up to 1.2 NSPE Handler Mode denial of service
4 months ago
A vulnerability classified as problematic has been found in ARM Trusted Firmware-M up to 1.2. Affected is an unknown function of the component NSPE Handler Mode. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2021-27562. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-30551 | Google Chrome up to 91.0.4472.77 V8 type confusion
4 months ago
A vulnerability was found in Google Chrome and classified as critical. Affected by this issue is some unknown functionality of the component V8. The manipulation leads to type confusion.
This vulnerability is handled as CVE-2021-30551. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-30554 | Google Chrome up to 91.0.4472.101 WebGL use after free
4 months ago
A vulnerability was found in Google Chrome. It has been classified as critical. This affects an unknown part of the component WebGL Handler. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2021-30554. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-30116 | Kaseya Virtual System Administrator up to 9.5.6 information disclosure
4 months ago
A vulnerability, which was classified as problematic, has been found in Kaseya Virtual System Administrator up to 9.5.6. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2021-30116. The attack can only be done within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-30563 | Google Chrome up to 91.0.4472.114 v8 type confusion
4 months ago
A vulnerability classified as critical was found in Google Chrome. This vulnerability affects unknown code of the component v8. The manipulation leads to type confusion.
This vulnerability was named CVE-2021-30563. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-28550 | Adobe Acrobat Reader use after free (apsb21-29)
4 months ago
A vulnerability classified as critical was found in Adobe Acrobat Reader up to 2017.011.30194/2020.001.30020/2021.001.20150. This vulnerability affects unknown code. The manipulation leads to use after free.
This vulnerability was named CVE-2021-28550. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-27561 | Yealink Device Management 3.6.0.20 services command injection
4 months ago
A vulnerability was found in Yealink Device Management 3.6.0.20 and classified as critical. Affected by this issue is some unknown functionality of the file /sm/api/v1/firewall/zone/services. The manipulation leads to command injection.
This vulnerability is handled as CVE-2021-27561. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
2024网安周 | 默安科技深度参与,共筑网络安全防线
4 months ago
网络安全为人民,网络安全靠人民