Aggregator
CVE-2024-12839 | Changing Information Technology CGFIDO up to 1.2.0 Device Authentication Login authentication replay
11 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Changing Information Technology CGFIDO up to 1.2.0. Affected by this issue is some unknown functionality of the component Device Authentication Login. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is handled as CVE-2024-12839. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13040 | Quanta Computer QOCA Aim Account Information User ID authorization
11 months 2 weeks ago
A vulnerability classified as very critical was found in Quanta Computer QOCA Aim. Affected by this vulnerability is an unknown functionality of the component Account Information Handler. The manipulation of the argument User ID leads to authorization bypass.
This vulnerability is known as CVE-2024-13040. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-12838 | Changing Information Technology CGFIDO up to 1.0.x Passwordless Login authentication bypass by assumed-immutable data
11 months 2 weeks ago
A vulnerability classified as very critical has been found in Changing Information Technology CGFIDO up to 1.0.x. Affected is an unknown function of the component Passwordless Login. The manipulation leads to authentication bypass by assumed-immutable data.
This vulnerability is traded as CVE-2024-12838. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11972 | Hunk Companion Plugin up to 1.8.x on WordPress REST API Endpoint authorization
11 months 2 weeks ago
A vulnerability was found in Hunk Companion Plugin up to 1.8.x on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component REST API Endpoint. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-11972. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-1999-0069 | Sun Solaris 2.5/2.5.1 ufsrestore memory corruption (ID 00169 / EDB-19533)
11 months 2 weeks ago
A vulnerability was found in Sun Solaris 2.5/2.5.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component ufsrestore. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-1999-0069. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-6996 | Apple iOS up to 9.0 IOAcceleratorFamily memory corruption (HT205370 / EDB-39380)
11 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Apple iOS up to 9.0. This affects an unknown part of the component IOAcceleratorFamily. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2015-6996. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2002-1773 | Mirabilis ICQ 2.6 X Beta on MacOS X Request memory corruption (EDB-21275 / XFDB-8085)
11 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Mirabilis ICQ 2.6 X Beta on MacOS X. Affected is an unknown function of the component Request Handler. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2002-1773. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
2024年度盘点之漏洞威胁:AI技术降低漏洞利用门槛,网络边缘设备成重灾区
11 months 2 weeks ago
2024年度十大漏洞盘点:最高影响设备量数以亿计
2024年度盘点之漏洞威胁:AI技术降低漏洞利用门槛,网络边缘设备成重灾区
11 months 2 weeks ago
数字时代,一切都架构在软件、网络、大数据之上。由于硬件、软件、协议在具体实现或操作系统安全策略上总会存在缺陷,所以漏洞无法避免。在即将过去的2024年中,安全漏洞数量持续增长,类型日趋多样化。据360
本月玩什么 | 夺宝奇兵、LOK Digital、纪念碑谷 3
11 months 2 weeks ago
本月玩什么 | 夺宝奇兵、LOK Digital、纪念碑谷 3 欢迎来到「本月玩什么」,本栏目将从作者个人角度出发,独立挑选一些本月新发售的游戏作品/内容做简要介绍、评论,不保证收录覆盖面,且并非每
Making the Web More Inclusive: Accessibility Testing with open source testing agents
11 months 2 weeks ago
Hey dev community! With the holidays right around the corner, it feels like the perfect time to talk
Melting Glaciers Slash Shipping Times—But Come With a Hidden Cost
11 months 2 weeks ago
Authors:(1) Jorge P. Rodrıguez, Instituto de Fiscia Interdisciplinar y Sistemas Complejos (IFISC),
CVE-2015-6995 | Apple Mac OS X up to 10.11.0 Disk Images memory corruption (HT205375 / EDB-39381)
11 months 2 weeks ago
A vulnerability was found in Apple Mac OS X up to 10.11.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component Disk Images. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2015-6995. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
网络安全信息与动态周报2024年第52期(12月23日-12月29日)
11 months 2 weeks ago
本周,互联网网络安全态势整体评价为良。
诚邀渠道合作伙伴共启新征程
11 months 2 weeks ago
元旦期间火绒将持续为您护航
11 months 2 weeks ago
Угроза в трубах: водоснабжение США «утопает» в кибератаках
11 months 2 weeks ago
Критическая инфраструктура оказалась бессильна перед натиском хакеров.
诚邀渠道合作伙伴共启新征程
11 months 2 weeks ago
随着业务的不断扩展和市场需求的增长,火绒安全寻求更多优秀的合作伙伴加入我们的行列。我们特别开启了渠道伙伴招募计划,期待与更多志同道合的伙伴一起把握行业趋势,共同开拓市场潜力,携手共创网络安全的美好未来
元旦期间火绒将持续为您护航
11 months 2 weeks ago