Aggregator
CVE-2014-7462 | teamlava Fashion Story: Neon 90's 1.5.6.5 X.509 Certificate cryptographic issues (VU#582497)
10 months 2 weeks ago
A vulnerability has been found in teamlava Fashion Story: Neon 90's 1.5.6.5 and classified as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-7462. The attack can only be done within the local network. There is no exploit available.
vuldb.com
Продукты «Лаборатории Касперского» исчезли из Google Play. Что делать пользователям?
10 months 2 weeks ago
Ситуация вокруг разработчика популярного антивирусного ПО продолжает накаляться.
CVE-2012-6151 | Apple Mac OS X up to 10.11.0 Net-SNMP resource management (HT205375 / EDB-38854)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Apple Mac OS X up to 10.11.0. This affects an unknown part of the component Net-SNMP. The manipulation leads to improper resource management.
This vulnerability is uniquely identified as CVE-2012-6151. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-3287 | Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 Secure Boot 7pk security (MS16-094 / Nessus ID 92025)
10 months 2 weeks ago
A vulnerability was found in Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Secure Boot. The manipulation leads to 7pk security features.
This vulnerability is handled as CVE-2016-3287. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2003-1478 | Microsoft Internet Explorer 6 HTML Engine Unicode memory corruption (EDB-22560 / XFDB-11971)
10 months 2 weeks ago
A vulnerability was found in Microsoft Internet Explorer 6. It has been declared as critical. This vulnerability affects unknown code of the component HTML Engine. The manipulation as part of Unicode leads to memory corruption.
This vulnerability was named CVE-2003-1478. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
LC 多云资产梳理工具已更新至 v1.1.0 版本
10 months 2 weeks ago
介绍LC(List Cloud)是一个多云攻击面资产梳理的工具,使用 LC 可以让甲方蓝队在管理多云时快速梳理出可能暴露在公网上的资产。LC 项目地址:github.com/wgpsec/lc
CVE-2010-3879 | FUSE up to 2.8.5 Filesystem link following (Bug 651183 / EDB-34953)
10 months 2 weeks ago
A vulnerability was found in FUSE up to 2.8.5. It has been rated as critical. Affected by this issue is some unknown functionality of the component Filesystem. The manipulation leads to link following.
This vulnerability is handled as CVE-2010-3879. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-5068 | phpFullAnnu 6.0 index.php mod sql injection (EDB-4449 / XFDB-36747)
10 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in phpFullAnnu 6.0. This issue affects some unknown processing of the file index.php. The manipulation of the argument mod leads to sql injection.
The identification of this vulnerability is CVE-2007-5068. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-5067 | Xitami HTTP Server HTTP Request If-Modified-Since memory corruption (EDB-4450 / Nessus ID 802025)
10 months 2 weeks ago
A vulnerability was found in Xitami HTTP Server. It has been classified as critical. This affects an unknown part of the component HTTP Request If-Modified-Since Handler. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2007-5067. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to replace the affected component with an alternative.
vuldb.com
CVE-2007-5098 | Dragonfrugal DFD Cart up to 1.1.4 product.control.config.php set_depth code injection (EDB-4451 / XFDB-36753)
10 months 2 weeks ago
A vulnerability has been found in Dragonfrugal DFD Cart up to 1.1.4 and classified as critical. Affected by this vulnerability is an unknown functionality in the library app.lib/product.control/core.php/product.control.config.php of the file product.control.config.php. The manipulation of the argument set_depth leads to code injection.
This vulnerability is known as CVE-2007-5098. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-5098 | DFD Cart customer.browse.list.php set_depth code injection (EDB-4451 / XFDB-36753)
10 months 2 weeks ago
A vulnerability classified as critical was found in DFD Cart. Affected by this vulnerability is an unknown functionality of the file customer.area/customer.browse.list.php. The manipulation of the argument set_depth leads to code injection.
This vulnerability is known as CVE-2007-5098. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-5099 | David Watters Helplink 0.1.0 Help show.php file code injection (EDB-4448 / BID-25782)
10 months 2 weeks ago
A vulnerability was found in David Watters Helplink 0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the file show.php of the component Help. The manipulation of the argument file leads to code injection.
This vulnerability is handled as CVE-2007-5099. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-5102 | Wordsmith 1.0 Rc1 config.inc.php _path code injection (EDB-4446 / XFDB-36746)
10 months 2 weeks ago
A vulnerability was found in Wordsmith 1.0 Rc1. It has been rated as critical. This issue affects some unknown processing of the file config.inc.php. The manipulation of the argument _path leads to code injection.
The identification of this vulnerability is CVE-2007-5102. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-5103 | Wordsmith 1.0 Rc1 config.inc.php _path path traversal (EDB-4446 / SA26924)
10 months 2 weeks ago
A vulnerability classified as critical has been found in Wordsmith 1.0 Rc1. Affected is an unknown function of the file config.inc.php. The manipulation of the argument _path leads to path traversal.
This vulnerability is traded as CVE-2007-5103. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-5069 | Massimo Chioni Mobile Entertainment Module 1 module_name path traversal (EDB-4447 / XFDB-36745)
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Massimo Chioni Mobile Entertainment Module 1. Affected is an unknown function. The manipulation of the argument module_name leads to path traversal.
This vulnerability is traded as CVE-2007-5069. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-1999-0774 | Martin Stover Mars NetWare Emulation 0.99 Directory Name Long String memory corruption (EDB-19485 / BID-617)
10 months 2 weeks ago
A vulnerability was found in Martin Stover Mars NetWare Emulation 0.99 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Name Handler. The manipulation as part of Long String leads to memory corruption.
This vulnerability is handled as CVE-1999-0774. The attack needs to be approached locally. Furthermore, there is an exploit available.
vuldb.com
WiLo: новая эра беспроводной связи
10 months 2 weeks ago
Как гибрид Wi-Fi и LoRa меняет представление о дальнобойной связи.
CVE-2019-10887 | Salicru SLC-20-cube3(5) cs121-SNMP v4.54.82.130611 /DataLog.csv Reflected injection (Exploit 152435 / EDB-46667)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Salicru SLC-20-cube3(5) cs121-SNMP v4.54.82.130611. Affected by this issue is some unknown functionality of the file /DataLog.csv?log. The manipulation leads to injection (Reflected).
This vulnerability is handled as CVE-2019-10887. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Глаза смарт-ТВ: как умные телевизоры используют ACR для слежки
10 months 2 weeks ago
Встроенная технология позволяет смарт-ТВ быть тайным шпионом в вашей гостиной.