Aggregator
【安全圈】可绕过安全防护!EDR Silencer红队工具遭黑客利用
10 months 3 weeks ago
【安全圈】朝鲜黑客利用FASTCash恶意软件从多个国家ATM机中窃取资金
10 months 3 weeks ago
【安全圈】腾讯云加强短信群发资质审核 需提交手持身份证拍照并按手印签署承诺书
10 months 3 weeks ago
VMware security advisory (AV24-597)
10 months 3 weeks ago
Canadian Centre for Cyber Security
CVE-2021-23017 | Oracle Communications Operations Monitor 3.4/4.2/4.3/4.4 nginx off-by-one (EDB-50973)
10 months 3 weeks ago
A vulnerability was found in Oracle Communications Operations Monitor 3.4/4.2/4.3/4.4. It has been classified as very critical. Affected is an unknown function of the component nginx. The manipulation leads to off-by-one.
This vulnerability is traded as CVE-2021-23017. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Web browser security: An overview (ITSAP.40.017)
10 months 3 weeks ago
Canadian Centre for Cyber Security
Web browser security: An overview (ITSAP.40.017)
10 months 3 weeks ago
Canadian Centre for Cyber Security
CVE-2008-0621 | SAP SAPSprint up to 6.28 memory corruption (EDB-5079 / Nessus ID 31121)
10 months 3 weeks ago
A vulnerability has been found in SAP SAPSprint up to 6.28 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2008-0621. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-0457 | Symantec Backupexec System Recovery 7.01 input validation (EDB-5078 / Nessus ID 30211)
10 months 3 weeks ago
A vulnerability classified as critical was found in Symantec Backupexec System Recovery 7.01. This vulnerability affects unknown code. The manipulation leads to improper input validation.
This vulnerability was named CVE-2008-0457. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-0772 | Mambo Com Doc index.php sid sql injection (EDB-5080 / BID-27679)
10 months 3 weeks ago
A vulnerability classified as critical was found in Mambo Com Doc. This vulnerability affects unknown code of the file index.php. The manipulation of the argument sid leads to sql injection.
This vulnerability was named CVE-2008-0772. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0714 | Mihalism Multi Host 3.0 users.php username sql injection (EDB-5074 / XFDB-40289)
10 months 3 weeks ago
A vulnerability was found in Mihalism Multi Host 3.0. It has been classified as critical. Affected is an unknown function of the file users.php. The manipulation of the argument username leads to sql injection.
This vulnerability is traded as CVE-2008-0714. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0719 | osCommerce Customer Testimonials 3.1 customer_testimonials.php testimonial_id sql injection (EDB-5075 / Nessus ID 31051)
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in osCommerce Customer Testimonials 3.1. This issue affects some unknown processing of the file customer_testimonials.php. The manipulation of the argument testimonial_id leads to sql injection.
The identification of this vulnerability is CVE-2008-0719. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0721 | Mambo Com Sermon 0.2 index.php gid sql injection (EDB-5076 / BID-27673)
10 months 3 weeks ago
A vulnerability has been found in Mambo Com Sermon 0.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument gid leads to sql injection.
This vulnerability is known as CVE-2008-0721. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
热点 | 又一汽车巨头遭勒索攻击,360为车企系好网络“安全带”
10 months 3 weeks ago
360护航“智驾”时代
US disrupts Anonymous Sudan DDoS operation, indicts 2 Sudanese brothers
10 months 3 weeks ago
The United States Department of Justice unsealed an indictment today against two Sudanese brothers suspected of being the operators of Anonymous Sudan, a notorious and dangerous hacktivist group known for conducting over 35,000 DDoS attacks in a year. [...]
Lawrence Abrams
CVE-2017-8907 | Atlassian Bamboo up to 5.15.6/6.0.0 Deployment Project access control (Nessus ID 101026 / BID-99090)
10 months 3 weeks ago
A vulnerability was found in Atlassian Bamboo up to 5.15.6/6.0.0. It has been rated as critical. This issue affects some unknown processing of the component Deployment Project Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2017-8907. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-9512 | Atlassian FishEye/Crucible up to 4.4.0 Permission Check mostActiveCommitters.do information disclosure (ID 803830)
10 months 3 weeks ago
A vulnerability classified as problematic was found in Atlassian FishEye and Crucible up to 4.4.0. This vulnerability affects unknown code of the file mostActiveCommitters.do of the component Permission Check. The manipulation leads to information disclosure.
This vulnerability was named CVE-2017-9512. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-12104 | wp-advanced-search Plugin 3.3.6 on WordPress Import sql injection
10 months 3 weeks ago
A vulnerability has been found in wp-advanced-search Plugin 3.3.6 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the component Import. The manipulation leads to sql injection.
This vulnerability is known as CVE-2020-12104. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2020-13822 | Elliptic Package 6.5.2 on node.js ECDSA Signature integer overflow
10 months 3 weeks ago
A vulnerability was found in Elliptic Package 6.5.2 on node.js. It has been classified as critical. This affects an unknown part of the component ECDSA Signature Handler. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2020-13822. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com