Aggregator
在spring-aop中挖掘新反序列化gadget-chain
11 months ago
目录• 前言• 挖掘过程• AbstractAspectJAdvice• ReflectiveMethodInvocation• JdkDynamicAopProxy• 调用链• 代码示例前言前阵子在
在spring-aop中挖掘新反序列化gadget-chain
11 months ago
CVE-2005-2961 | ProZilla Download Accelerator 1.3.7.4 get_string_ahref memory corruption (EDB-1238 / Nessus ID 19803)
11 months ago
A vulnerability has been found in ProZilla Download Accelerator 1.3.7.4 and classified as critical. This vulnerability affects the function get_string_ahref. The manipulation of the argument get_string_ahref leads to memory corruption.
This vulnerability was named CVE-2005-2961. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2003-1545 | Nukestyles Viewpage Module 6.5 on PHP-Nuke nukestyles.com file path traversal (EDB-22422 / Nessus ID 11472)
11 months ago
A vulnerability, which was classified as problematic, has been found in Nukestyles Viewpage Module 6.5 on PHP-Nuke. This issue affects some unknown processing of the file nukestyles.com. The manipulation of the argument file leads to path traversal.
The identification of this vulnerability is CVE-2003-1545. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Проект NEURONE: Британия удешевила производство критически важной термоядерной стали
11 months ago
Как Великобритания готовится к энергетической революции.
CVE-2011-2241 | Oracle Fusion Middleware 10.1.3.4.1 Business Intelligence Enterprise Edition denial of service (ID 120308 / SBV-32329)
11 months ago
A vulnerability classified as problematic has been found in Oracle Fusion Middleware 10.1.3.4.1. This affects an unknown part of the component Business Intelligence Enterprise Edition. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2011-2241. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2011-2245 | Oracle Sun Products Suite 9 Remote Code Execution (ID 119428 / SBV-32333)
11 months ago
A vulnerability has been found in Oracle Sun Products Suite 9 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2011-2245. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2011-2249 | Sun Solaris 5.10 TCP/IP denial of service (ID 119437 / XFDB-68639)
11 months ago
A vulnerability was found in Sun Solaris 5.10. It has been declared as problematic. This vulnerability affects unknown code of the component TCP/IP. The manipulation leads to denial of service.
This vulnerability was named CVE-2011-2249. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2011-2258 | Sun Solaris 5.11 Local Privilege Escalation (Nessus ID 53281 / ID 119433)
11 months ago
A vulnerability has been found in Sun Solaris 5.11 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to Local Privilege Escalation.
This vulnerability was named CVE-2011-2258. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2011-2259 | Sun Solaris 5.11 denial of service (ID 119432 / SBV-32371)
11 months ago
A vulnerability was found in Sun Solaris 5.11 and classified as critical. This issue affects some unknown processing. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2011-2259. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2012-0496 | Oracle MySQL Server 5.5.x (Nessus ID 57865 / ID 19657)
11 months ago
A vulnerability was found in Oracle MySQL Server 5.5.x. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2012-0496. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2007-0268 | Oracle Database Server 9.0.1.5 Replication sql injection (VU#221788 / Nessus ID 56055)
11 months ago
A vulnerability was found in Oracle Database Server 9.0.1.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Replication. The manipulation leads to sql injection.
This vulnerability is known as CVE-2007-0268. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-0324 | LizardTech DjVu Browser Plug-in up to 6.1.0 memory corruption (VU#522393 / Nessus ID 24670)
11 months ago
A vulnerability has been found in LizardTech DjVu Browser Plug-in up to 6.1.0 and classified as critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2007-0324. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-0323 | RIM TeamOn Import Object ActiveX control ActiveX Control toimport.dll setlanguage memory corruption (VU#869641 / EDB-3892)
11 months ago
A vulnerability classified as critical was found in RIM TeamOn Import Object ActiveX control. This vulnerability affects the function setlanguage in the library toimport.dll of the component ActiveX Control. The manipulation leads to memory corruption.
This vulnerability was named CVE-2007-0323. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2007-0217 | Microsoft Internet Explorer 5.01/6 FTP Client wininet.dll heap-based overflow (VU#613564 / EDB-3444)
11 months ago
A vulnerability classified as critical was found in Microsoft Internet Explorer 5.01/6. This vulnerability affects unknown code in the library wininet.dll of the component FTP Client. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2007-0217. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-0220 | Microsoft Exchange Server 2000 Outlook Web Access cross site scripting (VU#124113 / Nessus ID 25165)
11 months ago
A vulnerability was found in Microsoft Exchange Server 2000. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Outlook Web Access. The manipulation leads to basic cross site scripting.
This vulnerability is handled as CVE-2007-0220. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2008-5284 | IEA Software RadiusNT up to 5.1.25 numeric error (EDB-31128 / BID-27701)
11 months ago
A vulnerability has been found in IEA Software RadiusNT up to 5.1.25 and classified as critical. This vulnerability affects unknown code. The manipulation leads to numeric error.
This vulnerability was named CVE-2008-5284. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-0213 | Microsoft Exchange Server 2000/2003/2007 MIME Email memory corruption (VU#343145 / EDB-47076)
11 months ago
A vulnerability was found in Microsoft Exchange Server 2000/2003/2007. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component MIME Handler. The manipulation as part of Email leads to memory corruption.
This vulnerability is known as CVE-2007-0213. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-0197 | Apple Mac OS X 10.4.6 resource management (VU#240880 / Nessus ID 24354)
11 months ago
A vulnerability was found in Apple Mac OS X 10.4.6. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper resource management.
The identification of this vulnerability is CVE-2007-0197. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com