Aggregator
CVE-2013-2121 | Red Hat Openstack 3.0 code injection (ID 2631 / EDB-27045)
9 months 1 week ago
A vulnerability was found in Red Hat Openstack 3.0. It has been classified as critical. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2013-2121. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-1533 | Oracle JRE 1.6.0/1.7.0 memory corruption (RHSA-2012:1391 / EDB-26123)
9 months 1 week ago
A vulnerability was found in Oracle JRE 1.6.0/1.7.0. It has been classified as very critical. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2012-1533. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
OpenWrt One 路由器发布
9 months 1 week ago
OpenWrt 项目发布了专门为其量身打造的路由器 OpenWrt One,售价 89 美元。OpenWrt One 旨在尊重用户的软件自由,永远不会锁定,也永远不会变砖,用户可以自由修改、改造或修复。路由器本身是与 Banana Pi 合作制造的,使用了联发科的 MT7981B SoC,Wi-Fi 为联发科 MT7976C,1GB DDR4 内存,128 MiB SPI NAND + 4 MiB SPI NOR flash,两个以太网端口(2.5 GbE 和 1 GbE)、一个 USB 主机端口、用于 NVMe SSD 或类似设备的 M.2 2042 以及 mikroBUS 扩展头。产品通过阿里巴巴的 AliExpress 购买。
До 10 лет тюрьмы за утечки: Россия вводит исторические меры защиты данных
9 months 1 week ago
Что изменилось в регулировании персональной информации?
CVE-2011-0410 | CollabNet ScrumWorks 1.8.4 scrumworks.log cryptographic issues (VU#547167 / XFDB-64883)
9 months 1 week ago
A vulnerability was found in CollabNet ScrumWorks 1.8.4. It has been classified as problematic. Affected is an unknown function of the file server/scrumworks/data/hypersonic/scrumworks.log. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2011-0410. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2011-0411 | Postfix up to 2.7.2 access control (RHSA-2011:0423 / VU#555316)
9 months 1 week ago
A vulnerability was found in Postfix. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2011-0411. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-0393 | Cisco ASA up to 7.0.4.2 resource management (Nessus ID 52586 / ID 43206)
9 months 1 week ago
A vulnerability has been found in Cisco ASA up to 7.0.4.2 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2011-0393. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-0394 | Cisco Firewall Services Module Software up to 3.x resource management (Nessus ID 52586 / ID 43206)
9 months 1 week ago
A vulnerability was found in Cisco Firewall Services Module Software up to 3.x and classified as critical. Affected by this issue is some unknown functionality of the component Firewall Services Module. The manipulation leads to improper resource management.
This vulnerability is handled as CVE-2011-0394. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-1407 | Webhost Automation Helm Web Hosting Control Panel up to 3.2.10 domains.asp txtDomainName cross site scripting (EDB-27487 / XFDB-25470)
9 months 1 week ago
A vulnerability was found in Webhost Automation Helm Web Hosting Control Panel up to 3.2.10. It has been classified as problematic. This affects an unknown part of the file domains.asp of the component Control Panel. The manipulation of the argument txtDomainName leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2006-1407. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2002-0043 | Todd Miller sudo up to 1.6.3 P7 Mail Environment Variable privileges management (EDB-21227 / Nessus ID 13911)
9 months 1 week ago
A vulnerability was found in Todd Miller sudo up to 1.6.3 P7. It has been classified as critical. This affects an unknown part of the component Mail. The manipulation as part of Environment Variable leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2002-0043. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
微软信任的巴西 CA 签发了 google.com 的证书
9 months 1 week ago
巴西的一家政府 CA 机构 ICP-Brasil 被发现签发了 google.com 的证书。Google 和 Mozilla 早已拒绝信任该 CA,而软件巨人是唯一信任该 CA 的主流浏览器开发商,这意味着通过 Edge 或其它微软应用访问 google.com 的流量能被第三方拦截,但 Chrome 和 Firefox 不会。ICP-Brasil 的问题早在 2021 年就被报告并在 2022 年讨论之后被拒绝信任,但微软仍然决定信任它。
CVE-2009-2131 | 4homepages 4images up to 1.7.7 member.php user_homepage cross site scripting (EDB-8936 / XFDB-51090)
9 months 1 week ago
A vulnerability was found in 4homepages 4images up to 1.7.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file member.php. The manipulation of the argument user_homepage leads to cross site scripting.
This vulnerability is handled as CVE-2009-2131. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2142 | Zipstore Zip Store Chat 5.0 sql injection (EDB-8935 / SA35417)
9 months 1 week ago
A vulnerability was found in Zipstore Zip Store Chat 5.0. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2009-2142. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2148 | Campus Virtual-LMS id sql injection (EDB-8937 / ADV-2009-1583)
9 months 1 week ago
A vulnerability was found in Campus Virtual-LMS and classified as critical. This issue affects some unknown processing. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2009-2148. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2149 | Campus Virtual-LMS siteid cross site scripting (EDB-8937 / ADV-2009-1583)
9 months 1 week ago
A vulnerability was found in Campus Virtual-LMS. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument siteid leads to cross site scripting.
This vulnerability is traded as CVE-2009-2149. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2033 | Ricardo Alexandre De Oliveira Staudt Yogurt 0.3 index.php msg cross site scripting (EDB-8932 / BID-35324)
9 months 1 week ago
A vulnerability was found in Ricardo Alexandre De Oliveira Staudt Yogurt 0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument msg leads to cross site scripting.
This vulnerability is handled as CVE-2009-2033. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2034 | Ricardo Alexandre De Oliveira Staudt Yogurt 0.3 writemessage.php original sql injection (EDB-8932 / BID-35324)
9 months 1 week ago
A vulnerability was found in Ricardo Alexandre De Oliveira Staudt Yogurt 0.3. It has been classified as critical. This affects an unknown part of the file writemessage.php. The manipulation of the argument original leads to sql injection.
This vulnerability is uniquely identified as CVE-2009-2034. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-2101 | Castro Xl TorrentVolve 1.4 archive.php deleteTorrent path traversal (EDB-8931 / XFDB-51088)
9 months 1 week ago
A vulnerability was found in Castro Xl TorrentVolve 1.4. It has been classified as critical. Affected is an unknown function of the file archive.php. The manipulation of the argument deleteTorrent leads to path traversal.
This vulnerability is traded as CVE-2009-2101. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-4013 | IBM BigFix Platform 9.5 File Upload unrestricted upload (ID 154747 / EDB-47470)
9 months 1 week ago
A vulnerability classified as very critical was found in IBM BigFix Platform 9.5. Affected by this vulnerability is an unknown functionality of the component File Upload. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2019-4013. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com