Aggregator
CVE-2024-25711 | diffoscope up to 255 GPG File path traversal (Issue 361 / Nessus ID 211232)
10 months ago
A vulnerability classified as problematic was found in diffoscope up to 255. Affected by this vulnerability is an unknown functionality of the component GPG File Handler. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-25711. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-36087 | OAuthLib up to 3.2.0 on Python Redirect URI denial of service (GHSA-3pgj-pg6c-r5p7 / Nessus ID 211237)
10 months ago
A vulnerability was found in OAuthLib up to 3.2.0 on Python. It has been classified as problematic. This affects an unknown part of the component Redirect URI Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2022-36087. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-6662 | Oracle MySQL up to 5.5.52/5.6.33/5.7.15 Logging my.cnf access control (RHSA-2017:0184 / EDB-40360)
10 months ago
A vulnerability, which was classified as very critical, has been found in Oracle MySQL up to 5.5.52/5.6.33/5.7.15. This issue affects some unknown processing of the file my.cnf of the component Logging. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2016-6662. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply the suggested workaround.
vuldb.com
CVE-2022-31214 | Firejail up to 0.9.68 User Namespace join.c access control (Nessus ID 211247)
10 months ago
A vulnerability, which was classified as critical, was found in Firejail up to 0.9.68. Affected is an unknown function of the file join.c of the component User Namespace Handler. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2022-31214. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-2309 | libxml2 2.9.10/2.9.11/2.9.12/2.9.13/2.9.14 lxml null pointer dereference (Nessus ID 211245)
10 months ago
A vulnerability, which was classified as problematic, has been found in libxml2 2.9.10/2.9.11/2.9.12/2.9.13/2.9.14. Affected by this issue is some unknown functionality of the component lxml. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2022-2309. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-45506 | HAProxy up to 2.9.9/3.0.3/3.1-dev6 denial of service (Nessus ID 211246)
10 months ago
A vulnerability classified as problematic has been found in HAProxy up to 2.9.9/3.0.3/3.1-dev6. Affected is an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-45506. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-31107 | Grafana up to 8.3.9/8.4.9/8.5.8/9.0.2 authorization (GHSA-mx47-6497-3fv2 / Nessus ID 211248)
10 months ago
A vulnerability was found in Grafana up to 8.3.9/8.4.9/8.5.8/9.0.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect authorization.
This vulnerability is known as CVE-2022-31107. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24577 | libgit2 up to 1.6.4/1.7.1 src/libgit2/index.c git_index_add heap-based overflow (GHSA-j2v7-4f6v-gpg8 / Nessus ID 211258)
10 months ago
A vulnerability classified as critical was found in libgit2 up to 1.6.4/1.7.1. Affected by this vulnerability is the function git_index_add in the library src/libgit2/index.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-24577. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24575 | libgit2 up to 1.6.4/1.7.1 src/libgit2/revparse.c git_revparse_single resource consumption (GHSA-54mf-x2rh-hq9v / Nessus ID 211258)
10 months ago
A vulnerability was found in libgit2 up to 1.6.4/1.7.1 and classified as problematic. This issue affects the function git_revparse_single in the library src/libgit2/revparse.c. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2024-24575. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
NSO Group 而不是政府客户运营着间谍软件
10 months ago
间谍软件公司如何运营其业务?向客户出售间谍软件之后就置身事外,还是客户提供了监视目标之后由该公司植入恶意程序窃取情报之后交给客户?根据 WhatsApp 诉 NSO Group 案件本周公布的文件,间谍软件的运营完全由该公司而不是其客户完成。Meta 旗下的消息应用 WhatsApp 在 2019 年对以色列公司 NSO Group 提起诉讼,指控它在 2019 年 4 月 29 日到 5 月 10 日之间利用 WhatsApp 服务漏洞帮助客户入侵了至少 1400 名用户的手机。NSO 的客户包括了沙特阿拉伯、迪拜、印度、墨西哥、摩洛哥和卢旺达等国。WhatsApp 控诉的一个核心依据是运营间谍软件的是 NSO 而不是其政府客户。NSO 则坚称它不知道客户的目标,其产品旨在预防严重犯罪和恐怖主义,客户有义务不滥用间谍软件。根据 NSO 员工的证词,客户只需输入目标的电话号码,其余则由系统自动完成。换句话说,间谍软件的运行不是客户操作的。通过设计和持续更新其间谍软件 Pegasus,NSO 独自决定了访问 WhatsApp 服务器窃取目标手机上的信息。
Подросток превратил ложные вызовы в бизнес: 20 лет тюрьмы за своттинг
10 months ago
Суд разбирается в серии звонков, дезорганизовавших экстренные службы.
Google запустил умный анализатор звонков для борьбы с мошенниками
10 months ago
Уникальная система анализирует поведение приложений в реальном времени.
CVE-2000-0171 | AT Computing atsar 1.4 File Permission privileges management (EDB-19804 / BID-1048)
10 months ago
A vulnerability was found in AT Computing atsar 1.4 and classified as critical. Affected by this issue is some unknown functionality of the component File Permission Handler. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2000-0171. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
LLM attack中的API调用安全问题及靶场实践
10 months ago
分析了大语言模型LLM在进行API调用的过程中可能造成的安全问题,以及使用配套的靶场进行具象化的练习
3 240 км/ч на метане: революционный двигатель прошел первые испытания
10 months ago
Astro Mechanica испытала революционный двигатель, готовый к сверхзвуковым скоростям.
CVE-2022-32742 | Samba up to 4.14.13/4.15.8/4.16.3 SMB1 memory corruption (Nessus ID 211259)
10 months ago
A vulnerability was found in Samba up to 4.14.13/4.15.8/4.16.3. It has been classified as critical. Affected is an unknown function of the component SMB1. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2022-32742. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-32744 | Samba up to 4.14.13/4.15.8/4.16.3 Password Change key management (Nessus ID 211259)
10 months ago
A vulnerability was found in Samba up to 4.14.13/4.15.8/4.16.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Password Change Handler. The manipulation leads to key management error.
This vulnerability is known as CVE-2022-32744. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-32745 | Samba up to 4.13.13/4.14.9/4.15.1 LDAP memory corruption (Nessus ID 211259)
10 months ago
A vulnerability was found in Samba up to 4.13.13/4.14.9/4.15.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component LDAP Handler. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2022-32745. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-32746 | Samba up to 4.14.13/4.15.8/4.16.3 AD DC Database Audit Logging use after free (Nessus ID 211259)
10 months ago
A vulnerability classified as critical has been found in Samba up to 4.14.13/4.15.8/4.16.3. This affects an unknown part of the component AD DC Database Audit Logging. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2022-32746. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com