Aggregator
Linus Torvalds 痛恨大小写不敏感的文件系统
1 year 1 month ago
文件系统 Bcachefs 开发者 Kent Overstreet 关于大小写折叠问题的讨论引发了 Linux 作者对文件系统大小写不敏感的批评。Linus Torvalds 认为文件系统应该区分大小写,不区分是绝对错误的,一开始就不应该实现。他说文件系统的开发者永远不会吸取教训。区分大小写是个 bug,文件系统开发者可能太推崇旧的 FAT 文件系统,以至于试图以拙劣的方式重新创造它。
xrpl.js 库遭供应链攻击,超 290 万次下载用户私钥成窃取目标
1 year 1 month ago
安全客
CVE-2022-4603 | ppp pppdump pppdump/pppdump.c dumpppp spkt.buf/rpkt.buf array index
1 year 1 month ago
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index.
This vulnerability is traded as CVE-2022-4603. The attack needs to be done within the local network. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to apply a patch to fix this issue.
pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.
vuldb.com
CVE-2022-46872 | Mozilla Firefox up to 107 access control (Bug 1799156 / Nessus ID 208639)
1 year 1 month ago
A vulnerability was found in Mozilla Firefox up to 107 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2022-46872. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46874 | Mozilla Firefox up to 107 Remote Code Execution (Bug 1746139 / Nessus ID 208639)
1 year 1 month ago
A vulnerability was found in Mozilla Firefox up to 107. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to Remote Code Execution.
This vulnerability was named CVE-2022-46874. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46880 | Mozilla Thunderbird up to 102.5 WebGL use after free (Bug 1749292 / Nessus ID 208639)
1 year 1 month ago
A vulnerability, which was classified as critical, was found in Mozilla Thunderbird up to 102.5. This affects an unknown part of the component WebGL. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2022-46880. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46881 | Mozilla Thunderbird up to 102.5 WebGL memory corruption (Bug 1770930 / Nessus ID 208639)
1 year 1 month ago
A vulnerability was found in Mozilla Thunderbird up to 102.5 and classified as critical. This issue affects some unknown processing of the component WebGL. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2022-46881. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46878 | Mozilla Firefox up to 107 memory corruption (Nessus ID 208639)
1 year 1 month ago
A vulnerability classified as critical was found in Mozilla Firefox up to 107. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2022-46878. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46872 | Mozilla Thunderbird up to 102.5 access control (Bug 1799156 / Nessus ID 208639)
1 year 1 month ago
A vulnerability has been found in Mozilla Thunderbird up to 102.5 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2022-46872. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-46874 | Mozilla Thunderbird up to 102.5 Remote Code Execution (Bug 1746139 / Nessus ID 208639)
1 year 1 month ago
A vulnerability was found in Mozilla Thunderbird up to 102.5. It has been classified as critical. Affected is an unknown function. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2022-46874. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
NetRise ZeroLens identifies undisclosed software weaknesses
1 year 1 month ago
NetRise announced a new product, NetRise ZeroLens. NetRise’s category redefining platform creates a software asset inventory, which is critical to manage organizational risk. NetRise analyzes compiled code to find risk in software that actually executes on devices and other systems. This technique, known as binary composition analysis (BCA), identifies vulnerabilities not found through traditional vulnerability scanners or source code scans, prioritizing those before they are exploited. NetRise ZeroLens adds to the platform’s capabilities by analyzing … More →
The post NetRise ZeroLens identifies undisclosed software weaknesses appeared first on Help Net Security.
Industry News
恶意后门借 ViPNet 更新渗透,俄罗斯多行业数据安全拉响警报
1 year 1 month ago
安全客
«Шепни ИИ на ухо»: найден универсальный ключ к запретным знаниям всех нейросетей
1 year 1 month ago
Как из одного запроса сделать дыру в защите ИИ.
CVE-2025-39367 | SeventhQueen Kleo Plugin up to 5.4.3 on WordPress authorization
1 year 1 month ago
A vulnerability has been found in SeventhQueen Kleo Plugin up to 5.4.3 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-39367. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-32471 | SICK SICK FLX3-CPUC200 weak credentials
1 year 1 month ago
A vulnerability, which was classified as problematic, was found in SICK SICK FLX3-CPUC200. Affected is an unknown function. The manipulation leads to use of weak credentials.
This vulnerability is traded as CVE-2025-32471. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-32470 | SICK SICK FLX0-GPNT100/SICK FLX3-CPUC200 IP Address access control
1 year 1 month ago
A vulnerability, which was classified as critical, has been found in SICK SICK FLX0-GPNT100 and SICK FLX3-CPUC200. This issue affects some unknown processing of the component IP Address Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2025-32470. The attack may be initiated remotely. There is no exploit available.
vuldb.com
创新驱动,卡巴斯基凭借威胁情报实力领跑 SPARK 矩阵
1 year 1 month ago
安全客
CVE-2025-42598 | Seiko Epson Printer Driver on Windows default permission
1 year 1 month ago
A vulnerability classified as critical was found in Seiko Epson Printer Driver on Windows. This vulnerability affects unknown code. The manipulation leads to incorrect default permissions.
This vulnerability was named CVE-2025-42598. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-22235 | VMware Spring Boot up to 2.7.24/3.1.15/3.2.13/3.3.10/3.4.4 EndpointRequest.to input validation
1 year 1 month ago
A vulnerability classified as critical has been found in VMware Spring Boot up to 2.7.24/3.1.15/3.2.13/3.3.10/3.4.4. This affects the function EndpointRequest.to. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2025-22235. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com