Aggregator
.NET 安全基础入门学习知识库
1 year 7 months ago
.NET 一款通过rundll32执行PowerShell的工具
1 year 7 months ago
CrossBarking: как безобидные расширения превращают Opera в идеального шпиона
1 year 7 months ago
Новая уязвимость позволяет захватывать пользовательские аккаунты без лишних следов.
CVE-2017-2483 | Apple watchOS up to 3.1 Kernel memory corruption (HT207602 / EDB-41797)
1 year 7 months ago
A vulnerability was found in Apple watchOS up to 3.1. It has been rated as critical. This issue affects some unknown processing of the component Kernel. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2017-2483. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Прощай, теория струн? Новая модель Вселенной объясняет необъяснимое
1 year 7 months ago
Возможно, комос гораздо проще, чем нам казалось долгие годы.
传比亚迪季营收首次超特斯拉;苹果新 M4 MacBook Pro曝光;曝小红书测试引流至微信 | 极客早知道
1 year 7 months ago
OpenAI 计划 2026 年生产自研 AI 芯片;理想汽车正式成立出海部门;马斯克的秘密家庭庄园曝光
A Wave of Identity Security Reports Defines a Big Problem
1 year 7 months ago
There have been a wealth of r
派早报:Apple 发布 2024 款 MacBook Pro、OpenAI 将打造自研芯片等
1 year 7 months ago
你可能错过的新鲜事Apple 发布 2024 款 MacBook Pro10 月 30 日,Apple 公司发布 2024 款 MacBook Pro。2024 款 MacBook Pro 分为
印度对维基百科的诉讼可能产生深远影响
1 year 7 months ago
维基媒体基金会最近遵守印度德里高等法庭的命令删除了条目《Asian News International vs. Wikimedia Foundation》。这是维基百科历史上首次有英文文章被基金会删除。根据基金会公布的透明度报告,它自 2012 年以来共收到 5500 次内容删除和更改请求,它满足了不到 10 次请求,其中没有一次涉及英文条目。被删除的文章介绍的是印度亚洲国际新闻社(ANI)对维基媒体基金会提起的诽谤诉讼。ANI 提起诉讼是因为维基百科上有关 ANI 的条目称该新闻机构是政府的宣传喇叭,传播了亲政府的信息,散播了反对派的虚假信息。维基基金会此举引发了很多争议,专家担心此案的结果可能会对维基百科在全世界的运营产生深远影响。很多人都不喜欢维基百科上的文章描述,此案可能会鼓励更多人其尝试控制维基百科上的条目叙述。此案也可能会对言论自由产生“寒蝉效应”,鼓励更多的自我审查。
CVE-2017-2483 | Apple iOS up to 10.2 Kernel memory corruption (HT207617 / EDB-41797)
1 year 7 months ago
A vulnerability classified as critical was found in Apple iOS up to 10.2. This vulnerability affects unknown code of the component Kernel. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2483. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Под маской закона: шпионы КНДР и вымогатели Play создают новый киберальянс
1 year 7 months ago
Правительственные хакеры открывают новую эру вымогательских атак.
October 2024 Activity with Username chenzilong, (Thu, Oct 31st)
1 year 7 months ago
After reviewing the Top 10 Not So Common SSH Usernames and Passwords [1] published by Johannes 2 we
CVE-2024-10573 | mpg123 up to 1.32.7 Frankenstein's Monster buffer overflow
1 year 7 months ago
A vulnerability classified as critical has been found in mpg123 up to 1.32.7. This affects an unknown part. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-10573. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
三季度财报显示,网络安全行业继续第五个季度收入下滑,市场同比萎缩8.5%
1 year 7 months ago
第三季度网络安全上市公司财报显示,行业营收同比下降8.5%,季度收入已回落至疫情前水平。受经济环境收紧及市场需求减缓的影响,网络安全行业面临严峻挑战,逆风期持续。提升运营效率、加强成本管控并保持战略耐心,将是行业在逆境中取得稳健发展的关键。
CVE-2024-38819 | Vmware Spring Framework up to 5.3.40/6.0.24/6.1.13 WebMvc.fn/WebFlux.fn path traversal (Nessus ID 209652)
1 year 7 months ago
A vulnerability was found in Vmware Spring Framework up to 5.3.40/6.0.24/6.1.13. It has been rated as critical. Affected by this issue is some unknown functionality of the component WebMvc.fn/WebFlux.fn. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-38819. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48311 | Piwigo 14.5.0 Edit Album cross-site request forgery
1 year 7 months ago
A vulnerability was found in Piwigo 14.5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Edit Album. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-48311. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51419 | Ofweek Online Exhibition 1.0.0 cross site scripting
1 year 7 months ago
A vulnerability was found in Shenzhen Interconnection Harbor Network Technology Ofweek Online Exhibition 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-51419. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10006 | HashiCorp Consul/Consul Enterprise up to 1.20.0 HTTP Header http headers for scripting syntax
1 year 7 months ago
A vulnerability was found in HashiCorp Consul and Consul Enterprise up to 1.20.0 and classified as critical. This issue affects some unknown processing of the component HTTP Header Handler. The manipulation leads to improper neutralization of http headers for scripting syntax.
The identification of this vulnerability is CVE-2024-10006. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10005 | HashiCorp Consul/Consul Enterprise up to 1.20.0 HTTP Request path traversal
1 year 7 months ago
A vulnerability has been found in HashiCorp Consul and Consul Enterprise up to 1.20.0 and classified as critical. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-10005. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com