Aggregator
US seizes PopeyeTools cybercrime marketplace, charges administrators
2 days 12 hours ago
The U.S. has seized the cybercrime website 'PopeyeTools' and unsealed charges against three of its administrators, Abdul Ghaffar, Abdul Sami, and Javed Mirza, for selling stolen data. [...]
Bill Toulas
CVE-2015-5868 | Apple iOS up to 8.4.1 Kernel memory corruption (HT205212 / ID 370192)
2 days 12 hours ago
A vulnerability was found in Apple iOS up to 8.4.1. It has been classified as problematic. This affects an unknown part of the component Kernel. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2015-5868. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5896 | Apple iOS up to 8.4.1 Kernel memory corruption (HT205212 / ID 370192)
2 days 12 hours ago
A vulnerability was found in Apple iOS up to 8.4.1 and classified as problematic. This issue affects some unknown processing of the component Kernel. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2015-5896. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5868 | Apple Watch up to 1.0.2 Kernel memory corruption (HT205213 / ID 370192)
2 days 12 hours ago
A vulnerability classified as critical has been found in Apple Watch up to 1.0.2. This affects an unknown part of the component Kernel. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2015-5868. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5896 | Apple Watch up to 1.0.2 Kernel memory corruption (HT205213 / ID 370192)
2 days 12 hours ago
A vulnerability classified as critical was found in Apple Watch up to 1.0.2. This vulnerability affects unknown code of the component Kernel. The manipulation leads to memory corruption.
This vulnerability was named CVE-2015-5896. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5867 | Apple iOS up to 8.4.1 IOHIDFamily memory corruption (HT205212 / ID 370192)
2 days 12 hours ago
A vulnerability classified as critical has been found in Apple iOS up to 8.4.1. This affects an unknown part of the component IOHIDFamily. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2015-5867. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5863 | Apple iOS up to 8.4.1 IOStorageFamily Kernel Memory information disclosure (HT205212 / ID 370192)
2 days 12 hours ago
A vulnerability, which was classified as problematic, was found in Apple iOS up to 8.4.1. Affected is an unknown function of the component IOStorageFamily. The manipulation leads to information disclosure (Kernel Memory).
This vulnerability is traded as CVE-2015-5863. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5863 | Apple Watch up to 1.0.2 IOStorageFamily Kernel Memory information disclosure (HT205213 / ID 370192)
2 days 12 hours ago
A vulnerability was found in Apple Watch up to 1.0.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IOStorageFamily. The manipulation leads to information disclosure (Kernel Memory).
This vulnerability is handled as CVE-2015-5863. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
如何将DOM XSS升级为一键帐户接管(上集)
2 days 12 hours ago
CVE-2009-0707 | Powerscripts PowerClan 1.14a admin/index.php loginemail sql injection (EDB-7642 / XFDB-47702)
2 days 12 hours ago
A vulnerability was found in Powerscripts PowerClan 1.14a. It has been declared as critical. This vulnerability affects unknown code of the file admin/index.php. The manipulation of the argument loginemail leads to sql injection.
This vulnerability was named CVE-2009-0707. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-0177 | vmware Player up to 2.5.1 vmware-authd vmware-authd.exe resource management (EDB-7647 / Nessus ID 36117)
2 days 12 hours ago
A vulnerability classified as problematic has been found in vmware Player. Affected is an unknown function in the library vmwarebase.dll of the file vmware-authd.exe of the component vmware-authd. The manipulation leads to improper resource management.
This vulnerability is traded as CVE-2009-0177. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-0177 | VMware Player 2.5.1 vmware-authd denial of service (EDB-7647 / ID 116348)
2 days 12 hours ago
A vulnerability was found in VMware Player 2.5.1 and classified as problematic. Affected by this issue is some unknown functionality of the component vmware-authd. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2009-0177. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-0705 | PowerScripts PowerNews 2.5.4 news.php newsid sql injection (EDB-7641 / XFDB-47701)
2 days 12 hours ago
A vulnerability was found in PowerScripts PowerNews 2.5.4 and classified as critical. Affected by this issue is some unknown functionality of the file news.php. The manipulation of the argument newsid leads to sql injection.
This vulnerability is handled as CVE-2009-0705. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-0491 | Elecard Elecard MPEG Player 5.5 memory corruption (EDB-7637 / SA33355)
2 days 12 hours ago
A vulnerability was found in Elecard Elecard MPEG Player 5.5. It has been declared as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2009-0491. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-0597 | W3bcms w3b>cms 3.0.5 admin/index.php benutzername sql injection (EDB-7640 / BID-33082)
2 days 12 hours ago
A vulnerability has been found in W3bcms w3b>cms 3.0.5 and classified as critical. This vulnerability affects unknown code of the file admin/index.php. The manipulation of the argument benutzername leads to sql injection.
This vulnerability was named CVE-2009-0597. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
AI in Cybercrime: Hackers Exploiting OpenAI
2 days 12 hours ago
In a recent podcast interview with Cybercrime Magazine's host, Charlie Osborne, Heather Engel, Managing Partner at Strategic Cyber Partners, discusses reports from OpenAI that hackers are trying to use its tools for malicious purposes. The podcast can be listened to in its entirety below.
The post AI in Cybercrime: Hackers Exploiting OpenAI appeared first on Security Boulevard.
Lauren Yacono
CVE-2024-48747 | alist-tvbox 1.7.1 /atv-cli Privilege Escalation
2 days 12 hours ago
A vulnerability, which was classified as critical, has been found in alist-tvbox 1.7.1. This issue affects some unknown processing of the file /atv-cli. The manipulation leads to Privilege Escalation.
The identification of this vulnerability is CVE-2024-48747. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-29224 | GoCast 1.1.3 HTTP Request NAT os command injection (TALOS-2024-1961)
2 days 12 hours ago
A vulnerability classified as very critical was found in GoCast 1.1.3. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation of the argument NAT leads to os command injection.
This vulnerability was named CVE-2024-29224. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-28892 | GoCast 1.1.3 HTTP Request name os command injection (TALOS-2024-1960)
2 days 12 hours ago
A vulnerability classified as very critical has been found in GoCast 1.1.3. This affects an unknown part of the component HTTP Request Handler. The manipulation of the argument name leads to os command injection.
This vulnerability is uniquely identified as CVE-2024-28892. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com