Aggregator
CVE-2024-9514 | D-Link DIR-605L 2.13B01 BETA formSetDomainFilter curTime buffer overflow
11 months 2 weeks ago
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. This vulnerability affects the function formSetDomainFilter of the file /goform/formSetDomainFilter. The manipulation of the argument curTime leads to buffer overflow.
This vulnerability was named CVE-2024-9514. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9515 | D-Link DIR-605L 2.13B01 BETA /goform/formSetQoS curTime buffer overflow
11 months 2 weeks ago
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. This affects the function formSetQoS of the file /goform/formSetQoS. The manipulation of the argument curTime leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-9515. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9513 | Netadmin Software NetAdmin IAM up to 3.5 HTTP POST Request ReturnUserQuestionsFilled username information exposure
11 months 2 weeks ago
A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument username leads to information exposure through discrepancy.
This vulnerability is handled as CVE-2024-9513. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
It is recommended to apply restrictive firewalling.
vuldb.com
Submit #413874: D-Link DIR-605L 2.13B01 BETA Buffer Overflow [Accepted]
11 months 2 weeks ago
Submit #413874 / VDB-279214
noahze
Submit #413878: D-Link DIR-605L 2.13B01 BETA Buffer Overflow [Accepted]
11 months 2 weeks ago
Submit #413878 / VDB-279213
noahze
Recently patched CUPS flaw can be used to amplify DDoS attacks
11 months 2 weeks ago
error code: 1106
CVE-2024-6444 | zephyrproject-rtos Zephyr up to 3.6 ots_client.c olcp_ind_handler heap-based overflow
11 months 2 weeks ago
A vulnerability has been found in zephyrproject-rtos Zephyr up to 3.6 and classified as critical. Affected by this vulnerability is the function olcp_ind_handler of the file zephyr/subsys/bluetooth/services/ots/ots_client.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-6444. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-9071 | Easy Demo Importer Plugin up to 1.1.2 on WordPress SVG File Upload cross site scripting
11 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Easy Demo Importer Plugin up to 1.1.2 on WordPress. Affected is an unknown function of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9071. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9271 | Re WP Plugin up to 1.0.1 on WordPress SVG File Upload cross site scripting
11 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Re WP Plugin up to 1.0.1 on WordPress. This issue affects some unknown processing of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9271. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8499 | Checkout Field Editor Plugin up to 2.0.3 on WordPress render_review_request_notice cross site scripting
11 months 2 weeks ago
A vulnerability classified as problematic was found in Checkout Field Editor Plugin up to 2.0.3 on WordPress. This vulnerability affects the function render_review_request_notice. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-8499. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Submit #413498: NetAdmin Software NetAdmin 3.5 Username Enumeration [Accepted]
11 months 2 weeks ago
Submit #413498 / VDB-279212
tristao
E-Commerce Protection Lags Behind: Insights from the 2024 Global Bot Security Report
11 months 2 weeks ago
Community Chats Webinars LibraryHomeCybersecurity NewsFeaturesIndustry SpotlightNews R
CVE-2024-6442 | zephyrproject-rtos Zephyr up to 3.6 Global Buffer ascs.c ascs_cp_rsp_add out-of-bounds write (GHSA-m22j-ccg7-4v4h)
11 months 2 weeks ago
A vulnerability classified as critical has been found in zephyrproject-rtos Zephyr up to 3.6. This affects the function ascs_cp_rsp_add of the file /subsys/bluetooth/audio/ascs.c of the component Global Buffer Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-6442. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-47855 | JSON-lib up to 3.0.x Comment String util/JSONTokener.java Privilege Escalation
11 months 2 weeks ago
A vulnerability was found in JSON-lib up to 3.0.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file util/JSONTokener.java of the component Comment String Handler. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-47855. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6443 | zephyrproject-rtos Zephyr up to 3.6 zephyr/lib/utils/utf8.c utf8_trunc last_byte_p out-of-bounds (GHSA-gg46-3rh2-v765)
11 months 2 weeks ago
A vulnerability was found in zephyrproject-rtos Zephyr up to 3.6. It has been declared as critical. Affected by this vulnerability is the function utf8_trunc in the library zephyr/lib/utils/utf8.c. The manipulation of the argument last_byte_p leads to out-of-bounds read.
This vulnerability is known as CVE-2024-6443. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-44204 | Apple iOS/iPadOS up to 18.0 VoiceOver information disclosure (ID 121373)
11 months 2 weeks ago
A vulnerability was found in Apple iOS and iPadOS up to 18.0. It has been classified as problematic. Affected is an unknown function of the component VoiceOver. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-44204. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46658 | SyroTech SY-GOPON-8OLT-L3 1.6.0_240629 command injection
11 months 2 weeks ago
A vulnerability was found in SyroTech SY-GOPON-8OLT-L3 1.6.0_240629 and classified as critical. This issue affects some unknown processing. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2024-46658. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-47850 | OpenPrinting cups-browsed up to 2.4 HTTP POST Request denial of service
11 months 2 weeks ago
A vulnerability has been found in OpenPrinting cups-browsed up to 2.4 and classified as problematic. This vulnerability affects unknown code of the component HTTP POST Request Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-47850. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
3,8 Тбит/с: Cloudflare отражает рекордные DDoS-атаки
11 months 2 weeks ago
Трафик исходил из множества стран, включая Вьетнам и Бразилию.