Aggregator
I Studied 100+ SSRF Reports, and Here’s What I Learned
11 months 2 weeks ago
IDOR Leads To Account Takeover
11 months 2 weeks ago
IDOR Leads To Account Takeover
11 months 2 weeks ago
Why I Quit Bug Bounty Hunting :(
11 months 2 weeks ago
Why I Quit Bug Bounty Hunting :(
11 months 2 weeks ago
From Conflict to Collaboration: The Evolution of Vulnerability Disclosure
11 months 2 weeks ago
From Conflict to Collaboration: The Evolution of Vulnerability Disclosure
11 months 2 weeks ago
Critical Vulnerabilities in porte_plume plugin to Remote Exploits -$$$$ Bounty -CVE-2024–7954
11 months 2 weeks ago
Critical Vulnerabilities in porte_plume plugin to Remote Exploits -$$$$ Bounty -CVE-2024–7954
11 months 2 weeks ago
THM Smag Grotto: Learn Web Security, Privilege Escalation (Walkthrough)
11 months 2 weeks ago
Uncovering 0-Days: The Crucial Role of RFCs in Vulnerability Research and the Recent Windows…
11 months 2 weeks ago
HTB | Editorial — SSRF and CVE-2022–24439
11 months 2 weeks ago
Sensitive Data Leak using Cors Misconfiguration in prominent Domain Registrar
11 months 2 weeks ago
古尔曼:苹果AI将在18号推出;传英伟达4090显卡已停产;宋紫薇已从理想汽车离职 | 极客早知道
11 months 2 weeks ago
NVIDIA CEO 黄仁勋身价已超过英特尔公司总市值;消息称特斯拉计划以优质租赁为抵押,发行 7.83 亿美元的债券;美团联合创始人穆荣均套现 3.44 亿港元
CVE-2016-3140 | Linux Kernel up to 4.5.0 USB Descriptor digi_acceleport.c digi_port_init null pointer dereference (FEDORA-2016-81fd1b03aa / EDB-39537)
11 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 4.5.0 and classified as critical. This issue affects the function digi_port_init of the file drivers/usb/serial/digi_acceleport.c of the component USB Descriptor Handler. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2016-3140. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-1999-1477 | GNOME 1.0.8 --espeaker memory corruption (EDB-19512 / XFDB-3349)
11 months 2 weeks ago
A vulnerability was found in GNOME 1.0.8. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument --espeaker as part of Long Argument leads to memory corruption.
This vulnerability is known as CVE-1999-1477. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-4607 | Overlandstorage GuardianOS 5.1.041 Command Line Interface access control (EDB-9955 / XFDB-53881)
11 months 2 weeks ago
A vulnerability was found in Overlandstorage GuardianOS 5.1.041. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Line Interface. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2009-4607. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
CVE-2016-3453 | Oracle Solaris 10 Kernel denial of service (Nessus ID 92452 / ID 296004)
11 months 2 weeks ago
A vulnerability classified as critical was found in Oracle Solaris 10. This vulnerability affects unknown code of the component Kernel. The manipulation leads to denial of service.
This vulnerability was named CVE-2016-3453. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
RuCTF Finals 2024
11 months 2 weeks ago
Name: RuCTF Finals 2024 (an RuCTF Finals event.)
Date: Oct. 5, 2024, 5 a.m. — 06 Oct. 2024, 19:00 UTC [add to calendar]
Format: Attack-Defense
On-site
Location: Russia, Yekaterinburg
Offical URL: http://ructf.org/
Rating weight: 25.00
Event organizers: HackerDom
Date: Oct. 5, 2024, 5 a.m. — 06 Oct. 2024, 19:00 UTC [add to calendar]
Format: Attack-Defense
On-site
Location: Russia, Yekaterinburg
Offical URL: http://ructf.org/
Rating weight: 25.00
Event organizers: HackerDom