Aggregator
Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions
1 year 7 months ago
Four members of the now-defunct REvil ransomware operation have been sentenced to several years in
Yong05|小小輸入法標點符號使用全面解析
1 year 7 months ago
由
CVE-2016-1002 | Adobe Flash Player memory corruption (APSB16-08 / EDB-39608)
1 year 7 months ago
A vulnerability classified as critical was found in Adobe Flash Player up to 11.2.202.569/18.0.0.329/20.0.0.233/20.0.0.260/20.0.0.306. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2016-1002. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-13765 | QEMU 4.1.0 hw/core/loader.c rom_copy memory corruption (Nessus ID 209571)
1 year 7 months ago
A vulnerability was found in QEMU 4.1.0. It has been declared as critical. This vulnerability affects the function rom_copy of the file hw/core/loader.c. The manipulation leads to memory corruption.
This vulnerability was named CVE-2020-13765. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2020-11102 | QEMU 4.2.0 hw/net/tulip.c buffer overflow (Nessus ID 209571)
1 year 7 months ago
A vulnerability was found in QEMU 4.2.0. It has been rated as critical. This issue affects some unknown processing of the file hw/net/tulip.c. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2020-11102. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2020-11869 | QEMU up to 4.2.0 ATI VGA Emulation hw/display/ati-2d.c ati_2d_blt integer overflow (USN-4372-1 / Nessus ID 209571)
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in QEMU up to 4.2.0. Affected is the function ati_2d_blt of the file hw/display/ati-2d.c of the component ATI VGA Emulation. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2020-11869. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2020-13361 | QEMU 4.2.0 hw/audio/es1370.c es1370_transfer_audio out-of-bounds write (Nessus ID 209571)
1 year 7 months ago
A vulnerability classified as critical was found in QEMU 4.2.0. Affected by this vulnerability is the function es1370_transfer_audio of the file hw/audio/es1370.c. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2020-13361. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2020-10702 | QEMU 4.x PAuth Support missing cryptographic step (Nessus ID 209571)
1 year 7 months ago
A vulnerability was found in QEMU 4.x. It has been classified as problematic. Affected is an unknown function of the component PAuth Support. The manipulation leads to missing cryptographic step.
This vulnerability is traded as CVE-2020-10702. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-10761 | QEMU up to 5.0.0 NBD Server Request assertion (Nessus ID 209571)
1 year 7 months ago
A vulnerability, which was classified as problematic, has been found in QEMU up to 5.0.0. This issue affects some unknown processing of the component NBD Server. The manipulation as part of Request leads to reachable assertion.
The identification of this vulnerability is CVE-2020-10761. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-0985 | Adobe Flash Player memory corruption (RHSA-2016:0166 / EDB-39461)
1 year 7 months ago
A vulnerability classified as critical was found in Adobe Flash Player. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2016-0985. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-15890 | libslirp 4.0.0 ip_input.c ip_reass use after free (RHSA-2020:0775 / Nessus ID 209571)
1 year 7 months ago
A vulnerability classified as critical has been found in libslirp 4.0.0. Affected is the function ip_reass of the file ip_input.c. The manipulation leads to use after free.
This vulnerability is traded as CVE-2019-15890. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2019-12068 | QEMU up to 1:4.1-1 LSI SCSI Adapter Emulator lsi_execute_script infinite loop (USN-4191-1 / Nessus ID 209571)
1 year 7 months ago
A vulnerability classified as problematic was found in QEMU. Affected by this vulnerability is the function lsi_execute_script of the component LSI SCSI Adapter Emulator. The manipulation leads to infinite loop.
This vulnerability is known as CVE-2019-12068. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2019-15034 | QEMU 4.0.0 bochs-display.c buffer overflow (USN-4372-1 / Nessus ID 209571)
1 year 7 months ago
A vulnerability classified as critical has been found in QEMU 4.0.0. This affects an unknown part of the file hw/display/bochs-display.c. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2019-15034. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2002-1160 | Red Hat Linux 7.1/7.2/7.3/8.0 pam_xauth privileges management (VU#911505 / Nessus ID 14002)
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in Red Hat Linux 7.1/7.2/7.3/8.0. Affected by this issue is some unknown functionality of the component pam_xauth. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2002-1160. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
NASA 研发能从轨道降落的火星直升机
1 year 7 months ago
NASA 正在制定将另一架直升机送上火星的计划。该飞行器将在飞速冲入火星大气层后自行着陆,每天飞行数公里,同时携带科学设备。在机智号(Ingenuity)退役之后,NASA 正在研制名为 Chopper 的六旋翼无人机,它的航程和有效载荷能力都要大得多。Chopper 将重达35公斤,是 Ingenuity 的近 20 倍。无人机将能够在一分钟内飞行一公里,或在火星一天内飞行多公里,能携带 3 到 5 公斤的科学载荷。这种方法既有好处,也有问题,因为它增加了无人机的复杂性,但也省去了精心设计的软着陆系统。这种自动着陆能力还意味着 Chopper 进入火星大气层的位置不需要像以前的任务那样精确,这可以减少运载火箭的重量和燃料消耗。
SecWiki News 2024-10-26 Review
1 year 7 months ago
如何绕过数字钱包的安全支付机制 by ourren
ChatGPT在漏洞管理中的创新应用与自我启发式提示研究 by ourren
大网两级SOC与一级SOC技术架构差异 by swim
更多最新文章,请访问SecWiki
ChatGPT在漏洞管理中的创新应用与自我启发式提示研究 by ourren
大网两级SOC与一级SOC技术架构差异 by swim
更多最新文章,请访问SecWiki
CVE-2002-1152 | KDE 3.0/3.0.1/3.0.2 Konqueror Cookie missing encryption (XFDB-10083 / BID-5691)
1 year 7 months ago
A vulnerability was found in KDE 3.0/3.0.1/3.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Konqueror. The manipulation leads to missing encryption of sensitive data (Cookie).
This vulnerability is handled as CVE-2002-1152. The attack may be launched remotely. There is no exploit available.
vuldb.com
OnlyFans 支付给歌手的钱超过了 Spotify
1 year 7 months ago
英国知名歌手 Lily Allen 在流媒体服务 Spotify 上每月有近 800 万观众,她最近开始在 OnlyFans 上向约 1000 名订阅者提供足部照片。这位歌手透露 OnlyFans 给她的钱超过了 Spotify。据估计,在 Spotify 听一首歌,歌手可以获得大约 0.003 美元。如果歌手没有完全控制歌曲的出版发行,那么这笔钱还需要分成几份。Billboard 估计 Allen 在 Spotify 上的日收入为 4,077 美元,或每年约 140 万美元。OnlyFans 的月订阅费为 10 美元,1000 名订阅者意味着月收入 1 万美元,OnlyFans 提成 20%,意味着 Allen 月收入大约 8000 美元,她在 OnlyFans 的总收入不可能超过 Spotify,但单价显然远远高于流媒体的分成。
CVE-2002-1150 | Microsoft NetMeeting 3.01 Remote Desktop Sharing privileges management (XFDB-10119 / BID-5715)
1 year 7 months ago
A vulnerability was found in Microsoft NetMeeting 3.01. It has been classified as problematic. Affected is an unknown function of the component Remote Desktop Sharing. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2002-1150. Attacking locally is a requirement. There is no exploit available.
vuldb.com