Aggregator
News alert: INE shares guidance to help companies invest in year-end cybersecurity, networking training
1 year 7 months ago
Cary, NC, Oct. 28, 2024, Cy
CVE-2024-40774 | Apple macOS downgrade
1 year 7 months ago
A vulnerability was found in Apple macOS. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to algorithm downgrade.
The identification of this vulnerability is CVE-2024-40774. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40774 | Apple watchOS downgrade
1 year 7 months ago
A vulnerability classified as problematic has been found in Apple watchOS. Affected is an unknown function. The manipulation leads to algorithm downgrade.
This vulnerability is traded as CVE-2024-40774. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40774 | Apple tvOS downgrade
1 year 7 months ago
A vulnerability classified as problematic was found in Apple tvOS. Affected by this vulnerability is an unknown functionality. The manipulation leads to algorithm downgrade.
This vulnerability is known as CVE-2024-40774. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6224 | Send Email Only on Reply to My Comment Plugin up to 1.0.6 on WordPress cross-site request forgery
1 year 7 months ago
A vulnerability has been found in Send Email Only on Reply to My Comment Plugin up to 1.0.6 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-6224. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41517 | Feripro up to 2.2.3 uebersicht access control
1 year 7 months ago
A vulnerability was found in Feripro up to 2.2.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/benutzer/institution/rechteverwaltung/uebersicht. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-41517. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40096 | com.cascadialabs.who 15.0 on Android information disclosure
1 year 7 months ago
A vulnerability was found in com.cascadialabs.who 15.0 on Android. It has been declared as problematic. This vulnerability affects unknown code of the file com.cascadialabs.who. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-40096. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-39771 | Safie QBiC CLOUD CC-2L/One certificate validation
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in Safie QBiC CLOUD CC-2L and One. Affected is an unknown function. The manipulation leads to improper certificate validation.
This vulnerability is traded as CVE-2024-39771. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-41916 | HPE ClearPass Policy Manager up to 6.11.8/6.12.1 information disclosure
1 year 7 months ago
A vulnerability classified as problematic has been found in HPE ClearPass Policy Manager up to 6.11.8/6.12.1. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-41916. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Lawo AG vsm LTC Time Sync Path Traversal
1 year 7 months ago
Lawo AG vsm LTC Time Sync Path TraversalSEC Consult Vulnerability Lab Security Advisory < 20241024
UP-RESULT[pro-1.0] Multiple-SQLi
1 year 7 months ago
UP-RESULT[pro-1.0] Multiple-SQLi ## Titles: UP-RESULT[pro-1.0] Multiple-SQLi ## Author: nu11secur
ABB Cylon Aspect 3.08.01 getApplicationNamesJS.php Building/Project Name Exposure
1 year 7 months ago
ABB Cylon Aspect 3.08.01 (getApplicationNamesJS.php) Building/Project Name ExposureVendor: ABB Lt
Trust and risk in the AI era
1 year 7 months ago
55% of organizations say the security risks for their business have never been higher, according to Vanta. Yet the average company only dedicates 11% of its IT budget to security — far from the ideal allocation of 17%, according to business and IT leaders. Majority of companies do not provide opt-out for AI data training The rapid adoption of AI only adds to the risks with phishing attacks (33%), AI-based malware (32%), and compliance violations … More →
The post Trust and risk in the AI era appeared first on Help Net Security.
Help Net Security
T0级事故,亚信安全防病毒把微信误杀了?
1 year 7 months ago
亚信安全的防病毒产品更新病毒特征码后,竟然把微信当做病毒进行查杀,导致员工上班后发现微信已被清除。
CVE-2022-37020 | HP BIOS buffer overflow
1 year 7 months ago
A vulnerability was found in HP BIOS. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2022-37020. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-5661 | Citrix Hypervisor 8.2 CU1 LTSR improper control of interaction frequency (CTX677100)
1 year 7 months ago
A vulnerability was found in Citrix Hypervisor 8.2 CU1 LTSR. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to improper control of interaction frequency.
This vulnerability was named CVE-2024-5661. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38951 | PX4-Autopilot 1.12.3 MavLink Message denial of service
1 year 7 months ago
A vulnerability classified as problematic has been found in PX4-Autopilot 1.12.3. This affects an unknown part of the component MavLink Message Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-38951. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-5071 | Bookster Plugin up to 1.1.0 on WordPress Appointment authorization
1 year 7 months ago
A vulnerability was found in Bookster Plugin up to 1.1.0 on WordPress. It has been classified as problematic. Affected is an unknown function of the component Appointment Handler. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2024-5071. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-25479 | Realtek PCIe Card Reader/RtsUer Driver for USB Card Reader Kernel Memory RtsPer.sys information disclosure
1 year 7 months ago
A vulnerability has been found in Realtek PCIe Card Reader and RtsUer Driver for USB Card Reader and classified as problematic. This vulnerability affects unknown code in the library RtsPer.sys of the component Kernel Memory Handler. The manipulation leads to information disclosure.
This vulnerability was named CVE-2022-25479. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com