Aggregator
CVE-2015-7987 | mDNSResponder up to 625.41.1 GetValueForMACAddr memory corruption (VU#143335 / BID-91323)
10 months 1 week ago
A vulnerability was found in mDNSResponder up to 625.41.1. It has been classified as very critical. Affected is the function GetValueForMACAddr. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2015-7987. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
A new fileless variant of Remcos RAT observed in the wild
10 months 1 week ago
Fortinet researchers discovered a new phishing campaign spreading a variant of the commercial malware Remcos RAT. Fortinet’s FortiGuard Labs recently uncovered a phishing campaign spreading a new variant of the Remcos RAT. Remcos is a commercial remote administration tool (RAT) that is sold online to allow buyers remote control over computers. Threat actors use Remcos […]
Pierluigi Paganini
Veeam Backup & Replication 漏洞在新的 Frag 勒索软件攻击中被重复使用
10 months 1 week ago
安全客
CVE-2006-2887 | Aspburst myNewsletter 1.1.2 Login validatelogin.asp UserName sql injection (EDB-1884 / XFDB-26947)
10 months 1 week ago
A vulnerability, which was classified as critical, was found in Aspburst myNewsletter 1.1.2. Affected is an unknown function of the file validatelogin.asp of the component Login. The manipulation of the argument UserName leads to sql injection.
This vulnerability is traded as CVE-2006-2887. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Roblox开发人员受到恶意npm包的供应链攻击
10 months 1 week ago
安全客
美国机构提醒员工限制使用电话,因为 Salt Typhoon 黑客攻击了电信提供商
10 months 1 week ago
安全客
CVE-2024-50219 | Linux Kernel up to 5.15.170/6.1.115/6.6.59/6.11.6 Network Packet unreserve_highatomic_pageblock allocation of resources
10 months 1 week ago
A vulnerability was suspected in Linux Kernel up to 5.15.170/6.1.115/6.6.59/6.11.6. Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all.
vuldb.com
SpyNote 恶意软件:虚假防病毒软件在复杂的新活动中以 Android 用户为目标
10 months 1 week ago
安全客
CVE-2024-11079 | Red Hat Ansible hostvars Object information disclosure
10 months 1 week ago
A vulnerability classified as problematic was found in Red Hat Ansible. Affected by this vulnerability is an unknown functionality of the component hostvars Object Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-11079. The attack can only be done within the local network. There is no exploit available.
vuldb.com
QSC 恶意软件框架:CloudComputating Group 网络间谍武器库中的新工具
10 months 1 week ago
安全客
CVE-2024-10345 | Helix Core up to 2024.1 shutdown resource consumption
10 months 1 week ago
A vulnerability classified as critical has been found in Helix Core up to 2024.1. Affected is the function shutdown. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-10345. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34014 | Acronis Backup Plugin for cPanel & WHM on Linux symlink
10 months 1 week ago
A vulnerability was found in Acronis Backup Plugin for cPanel & WHM, Backup Extension for Plesk and Backup Plugin for DirectAdmin on Linux. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to symlink following.
The identification of this vulnerability is CVE-2024-34014. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34015 | Acronis Backup Plugin for cPanel & WHM up to 817 on Linux symlink
10 months 1 week ago
A vulnerability was found in Acronis Backup Plugin for cPanel & WHM up to 817 on Linux. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to symlink following.
This vulnerability was named CVE-2024-34015. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43429 | Moodle up to 4.1.11/4.2.8/4.3.5/4.4.1 Gradebook Report information disclosure
10 months 1 week ago
A vulnerability was found in Moodle up to 4.1.11/4.2.8/4.3.5/4.4.1. It has been classified as problematic. This affects an unknown part of the component Gradebook Report. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-43429. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
FakeBat Loader 重新出现:恶意 Google Ads 针对 Notion 用户
10 months 1 week ago
安全客
CVE-2024-43427 | Moodle up to 4.1.11/4.2.8/4.3.5/4.4.1 Site Administration Preset Export missing initialization
10 months 1 week ago
A vulnerability was found in Moodle up to 4.1.11/4.2.8/4.3.5/4.4.1 and classified as problematic. Affected by this issue is some unknown functionality of the component Site Administration Preset Export. The manipulation leads to missing initialization of a variable.
This vulnerability is handled as CVE-2024-43427. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-23337 | lodash up to 4.17.20 Template command injection (SNYK-JS-LODASH-1040724)
10 months 1 week ago
A vulnerability has been found in lodash up to 4.17.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to command injection.
This vulnerability is known as CVE-2021-23337. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-28500 | lodash up to 4.17.20 Regular Expression denial of service (SNYK-JS-LODASH-1018905)
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in lodash up to 4.17.20. Affected is an unknown function of the component Regular Expression Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2020-28500. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Black Suit
10 months 1 week ago
cohenido