Aggregator
入侵餐厅菜单软件修改过敏信息的前迪士尼员工被判三年
4 months 2 weeks ago
佛罗里达州居民 Michael Scheuer 因在解雇后入侵迪士尼乐园 Walt Disney World 餐厅使用的第三方菜单制作软件,修改了菜单上的过敏信息,在菜单里加入了脏话,将菜单使用的字体全部改为 Wingdings,他被判 3 年监禁以及接近 69 万美元的赔偿金——大部分判给迪士尼。Scheuer 因为不当行为被解雇,解雇前担任菜单制作经理,他利用了尚未取消的密码访问了菜单系统。含有花生的食物对花生过敏者可能是致命的。
Triada 木马病毒不断升级:预装 Android 恶意软件现已嵌入设备固件
4 months 2 weeks ago
安全客
2024年在野零日漏洞利用分析(上)
4 months 2 weeks ago
在野0day利用分析
2024年在野零日漏洞利用分析(上)
4 months 2 weeks ago
在野0day利用分析
CVE-2008-0888 | Info-ZIP unzip inflate.c inflate_dynamic memory corruption (Nessus ID 67672 / ID 115824)
4 months 2 weeks ago
A vulnerability was found in Info-ZIP unzip and classified as very critical. This issue affects the function inflate_dynamic of the file inflate.c. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2008-0888. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-14865 | grub2 grub2-set-bootflag privilege defined with unsafe actions (RHSA-2020:0335 / Nessus ID 212124)
4 months 2 weeks ago
A vulnerability classified as problematic has been found in grub2. Affected is an unknown function of the component grub2-set-bootflag. The manipulation leads to privilege defined with unsafe actions.
This vulnerability is traded as CVE-2019-14865. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-45193 | CBRN-Analysis up to 21 Public Profile permission
4 months 2 weeks ago
A vulnerability classified as critical has been found in CBRN-Analysis up to 21. This affects an unknown part of the component Public Profile. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2022-45193. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-3980 | Sophos Mobile Managed On-Premises up to 9.7.4 XML server-side request forgery
4 months 2 weeks ago
A vulnerability was found in Sophos Mobile Managed On-Premises up to 9.7.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component XML Handler. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2022-3980. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-45461 | Veritas NetBackup up to 10.1 on Linux/Unix Java Admin Console os command injection
4 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Veritas NetBackup up to 10.1 on Linux/Unix. This affects an unknown part of the component Java Admin Console. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2022-45461. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-44384 | rConfig 3.9.6 PHP File unrestricted upload (Exploit 49783 / EDB-49783)
4 months 2 weeks ago
A vulnerability was found in rConfig 3.9.6. It has been declared as critical. This vulnerability affects unknown code of the component PHP File Handler. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2022-44384. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-44402 | oretnom23 Automotive Shop Management System 1.0 Master.php?f=delete_transaction sql injection
4 months 2 weeks ago
A vulnerability was found in oretnom23 Automotive Shop Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /asms/classes/Master.php?f=delete_transaction. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2022-44402. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-44403 | Automotive Shop Management System 1.0 manage_user ID sql injection
4 months 2 weeks ago
A vulnerability has been found in Automotive Shop Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /asms/admin/?page=user/manage_user. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2022-44403. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-36785 | D-Link G integrated Access Device4 Web Interface login.asp Username authorization
4 months 2 weeks ago
A vulnerability was found in D-Link G integrated Access Device4. It has been classified as critical. This affects an unknown part of the file login.asp of the component Web Interface. The manipulation of the argument Username leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2022-36785. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-44725 | OPC Foundation Local Discovery Server up to 1.04.403.478 Configuration File race condition
4 months 2 weeks ago
A vulnerability classified as critical was found in OPC Foundation Local Discovery Server up to 1.04.403.478. This vulnerability affects unknown code of the component Configuration File Handler. The manipulation leads to race condition.
This vulnerability was named CVE-2022-44725. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-44001 | BACKCLICK Professional 5.9.63 CORBA Back-End Services improper authentication (SYSS-2022-035)
4 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in BACKCLICK Professional 5.9.63. Affected by this issue is some unknown functionality of the component CORBA Back-End Services. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2022-44001. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
Мозг + квантовые компьютеры = NeuroSA: новый алгоритм находит решения там, где другие ИИ сдаются
4 months 2 weeks ago
Система ускорит создание лекарств в 100 раз, мощно прокачает логистику…
CVE-2025-3200:Wiesemann 和 Theis Com-Server 设备因弃用的 TLS 协议而暴露
4 months 2 weeks ago
安全客
Introducing Mend’s Integration with Microsoft Defender for Cloud
4 months 2 weeks ago
Mend.io now integrates with Microsoft Defender for Cloud, bringing intelligent open source security insights into cloud workflows.
The post Introducing Mend’s Integration with Microsoft Defender for Cloud appeared first on Security Boulevard.
Mend.io Communications
SecAI Debuts at RSA 2025, Redefining Threat Investigation with AI
4 months 2 weeks ago
San Francisco, United States, 29th April 2025, CyberNewsWire
The post SecAI Debuts at RSA 2025, Redefining Threat Investigation with AI appeared first on Security Boulevard.
cybernewswire