Aggregator
CVE-2021-44665 | Xerte up to 3.10.3 Project File download.php pathname traversal (EDB-50794)
11 months ago
A vulnerability has been found in Xerte up to 3.10.3 and classified as critical. This vulnerability affects unknown code of the file download.php of the component Project File Handler. The manipulation leads to pathname traversal.
This vulnerability was named CVE-2021-44665. The attack needs to be done within the local network. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Dell admin pw
11 months ago
I bought an old Dell laptop. Circa 2012 or so. So it's pretty old. When I boot, it says it
CVE-2018-4323 | Apple tvOS up to 11.4.1 memory corruption (EDB-45484 / Nessus ID 119323)
11 months ago
A vulnerability classified as critical was found in Apple tvOS up to 11.4.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2018-4323. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-6504 | Wireshark up to 1.12.12 NDS Dissector packet-ncp2222.inc null pointer dereference (EDB-40194 / Nessus ID 93342)
11 months ago
A vulnerability has been found in Wireshark up to 1.12.12 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file epan/dissectors/packet-ncp2222.inc of the component NDS Dissector. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2016-6504. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2509 | Apple macOS up to 10.12.4 Kernel Memory access control (HT207797 / EDB-42046)
11 months ago
A vulnerability was found in Apple macOS up to 10.12.4. It has been classified as problematic. This affects an unknown part of the component Kernel. The manipulation leads to improper access controls (Memory).
This vulnerability is uniquely identified as CVE-2017-2509. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-1999-0844 | Deerfield MDaemon 2.8.5/2.8.6 URL denial of service (EDB-19639 / Nessus ID 10139)
11 months ago
A vulnerability, which was classified as problematic, has been found in Deerfield MDaemon 2.8.5/2.8.6. Affected by this issue is some unknown functionality of the component URL Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-1999-0844. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Phishing texts trick Apple iMessage users into disabling protection
11 months ago
Cybercriminals are exploiting a trick to turn off Apple iMessage's built-in phishing protect
KANN MAN HIER HACKEN LERNEN ?
11 months ago
Phishing texts trick Apple iMessage users into disabling protection
11 months ago
Cybercriminals are exploiting a trick to turn off Apple iMessage's built-in phishing protection for a text and trick users into re-enabling disabled phishing links. [...]
Lawrence Abrams
CVE-2001-0762 | su-wrapper 1.1.1 memory corruption (EDB-20906 / BID-2837)
11 months ago
A vulnerability, which was classified as problematic, has been found in su-wrapper 1.1.1. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2001-0762. The attack needs to be approached locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-1088 | Phpoutsourcing Zorum up to 3.5 index.php method cross site scripting (EDB-23011 / XFDB-12867)
11 months ago
A vulnerability has been found in Phpoutsourcing Zorum up to 3.5 and classified as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument method leads to basic cross site scripting.
This vulnerability was named CVE-2003-1088. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2001-0782 | KDE ktvision up to 0.1.1-271 Configuration File symlink (EDB-20961 / XFDB-6741)
11 months ago
A vulnerability, which was classified as critical, was found in KDE ktvision up to 0.1.1-271. Affected is an unknown function of the component Configuration File. The manipulation leads to symlink following.
This vulnerability is traded as CVE-2001-0782. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Generating randomized long usernames for Jamf Pro standard user accounts
11 months ago
Home > Jamf Pro > Generating randomized long usernames for Jamf Pro standard user accountsG
CVE-2002-0931 | Luis Bernardo MyHelpDesk 2002-05-09 index.php id cross site scripting (EDB-21526 / XFDB-9320)
11 months ago
A vulnerability, which was classified as problematic, was found in Luis Bernardo MyHelpDesk 2002-05-09. This affects an unknown part of the file index.php. The manipulation of the argument id leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2002-0931. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-24499 | Workreap Theme up to 2.2.1 on WordPress uploads/workreap-temp unrestricted upload (EDB-51510)
11 months ago
A vulnerability was found in Workreap Theme up to 2.2.1 on WordPress and classified as critical. Affected by this issue is the function workreap_award_temp_file_uploader/workreap_temp_file_uploader of the file uploads/workreap-temp. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2021-24499. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Check out a botnet (c2) framework I made!
11 months ago
The Vanity Press in Academia
11 months ago
I’ve never been a regular resident of the ivory halls of academia, but Mich Kabay recently made me aware of an article about legitimate scientific journals driven to distraction by being flooded with commentary apparently reflecting a surge in the use of artificial intelligence rather than legitimate research and analysis. The Science article claims that […]
The post The Vanity Press in Academia appeared first on Security Boulevard.
David Harley
CVE-2018-16226 | Mitel MiVoice Office 400 up to R5.0 start.asp error Reflected cross site scripting
11 months ago
A vulnerability, which was classified as problematic, has been found in Mitel MiVoice Office 400 up to R5.0. This issue affects some unknown processing of the file start.asp. The manipulation of the argument error leads to cross site scripting (Reflected).
The identification of this vulnerability is CVE-2018-16226. The attack may be initiated remotely. There is no exploit available.
vuldb.com
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 28
11 months ago
Pro-Russia hackers NoName057 targe