Aggregator
CVE-2024-12641 | Chunghwa Telecom TenderDocTransfer up to 0.41.156 API cross site scripting
1 year ago
A vulnerability classified as problematic was found in Chunghwa Telecom TenderDocTransfer up to 0.41.156. This vulnerability affects unknown code of the component API. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-12641. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9678 | Trellix DLP Extension 11.11.1.3 sql injection
1 year ago
A vulnerability classified as critical has been found in Trellix DLP Extension 11.11.1.3. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-9678. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-12643 | Chunghwa Telecom tbm-client up to 0.3.20 API cross-site request forgery
1 year ago
A vulnerability was found in Chunghwa Telecom tbm-client up to 0.3.20. It has been rated as problematic. Affected by this issue is some unknown functionality of the component API. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-12643. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-12642 | Chunghwa Telecom TenderDocTransfer up to 0.41.156 API cross-site request forgery
1 year ago
A vulnerability was found in Chunghwa Telecom TenderDocTransfer up to 0.41.156. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component API. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-12642. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2014-6600 | Oracle Solaris 11 File System denial of service (Nessus ID 80940 / ID 123074)
1 year ago
A vulnerability was found in Oracle Solaris 11. It has been rated as problematic. This issue affects some unknown processing of the component File System. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2014-6600. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-9491 | illumos devzvol_readdir null pointer dereference (ID 123074 / XFDB-99686)
1 year ago
A vulnerability was found in illumos. It has been rated as problematic. This issue affects the function devzvol_readdir. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2014-9491. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2014-3961 | Xnau Participants Database up to 1.5.4.0 query sql injection (ID 126878 / EDB-33613)
1 year ago
A vulnerability was found in Xnau Participants Database up to 1.5.4.0. It has been classified as critical. Affected is an unknown function. The manipulation of the argument query leads to sql injection.
This vulnerability is traded as CVE-2014-3961. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
LW ROUNDTABLE: Lessons learned from the headline-grabbing cybersecurity incidents of 2024
1 year ago
It’s all too clear that the cybersecurity community, once more, is facing elevated challenges as well as opportunities.
Part one of a four-part seriesThe world’s reliance on interconnected digital infrastructure continues to deepen, even as the threats facing it … (more…)
The post LW ROUNDTABLE: Lessons learned from the headline-grabbing cybersecurity incidents of 2024 first appeared on The Last Watchdog.
The post LW ROUNDTABLE: Lessons learned from the headline-grabbing cybersecurity incidents of 2024 appeared first on Security Boulevard.
bacohido
LW ROUNDTABLE: Lessons learned from the headline-grabbing cybersecurity incidents of 2024
1 year ago
By Byron V. AcohidoIt’s all too clear that the cybersecurity community, once more, is facing elev
Task scams — новый вид азартных игр: люди теряют всё, надеясь заработать
1 year ago
Как лайки на видео превратились в финансовую катастрофу
CVE-2014-3970 | PulseAudio up to 5.0 pa_rtp_recv denial of service (Nessus ID 82387 / ID 167188)
1 year ago
A vulnerability, which was classified as problematic, has been found in PulseAudio up to 5.0. Affected by this issue is the function pa_rtp_recv. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2014-3970. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2014-3977 | IBM AIX 6.1/7.1 libodm link following (EDB-33725 / Nessus ID 74193)
1 year ago
A vulnerability was found in IBM AIX 6.1/7.1. It has been classified as critical. This affects an unknown part in the library libodm. The manipulation leads to link following.
This vulnerability is uniquely identified as CVE-2014-3977. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2014-3980 | Daiki Ueno libfep 0.0.5/0.0.6/0.0.7/0.0.8/0.0.9 Privileges access control (Nessus ID 76097 / ID 122191)
1 year ago
A vulnerability, which was classified as problematic, was found in Daiki Ueno libfep 0.0.5/0.0.6/0.0.7/0.0.8/0.0.9. This affects an unknown part of the component Privileges. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2014-3980. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
开发者的执行力极强:一键将Office文档转换为MD格式的在线工具已上线
1 year ago
你住的城市下不下雪?用这份「雪天片单」感受浪漫季节
1 year ago
你住的城市下不下雪?用这份「雪天片单」感受浪漫季节也许你也会在每年冬天期待一场大雪,羡慕着千里之外白雪纷飞时,人们拉着手风琴在雪中的操场合唱的夜晚。在关于雪的回忆里,有多少是来自那些经典的影视作品。在
38C3: Self-organized Sessions
1 year ago
TL;DRWorkshops, Gruppentreffen, Kurzvorträge, … fassen wir als Self-organized Sessions zu
Submit #455071: htmly cms htmly cms v3.0.2<= Improper Neutralization of Alternate XSS Syntax [Duplicate]
1 year ago
Submit #455071 / VDB-194009
Lysir
绿盟科技威胁周报(2024.12.09-2024.12.15)
1 year ago
阅读: 9一、威胁通告1.Apache Struts任意文件上传漏洞S2-067(CVE-2024-53677)通告【标签】CVE-2024-53677【发布
CVE-2014-3984 | Libav up to 0.8.11 memory corruption (USN-2244-1 / Nessus ID 74494)
1 year ago
A vulnerability has been found in Libav up to 0.8.11 and classified as very critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2014-3984. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com