Aggregator
CVE-2025-5278 | GNU Coreutils 7.2 Key Specification heap-based overflow (Nessus ID 237938)
2 months ago
A vulnerability was found in GNU Coreutils 7.2. It has been classified as critical. This affects an unknown part of the component Key Specification. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-5278. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-48708 | Artifex Ghostscript up to 10.05.0 base/gslibctx.c gs_lib_ctx_stash_sanitized_arg improper removal of sensitive information before storage or transfer (Nessus ID 237937)
2 months ago
A vulnerability, which was classified as problematic, was found in Artifex Ghostscript up to 10.05.0. Affected is the function gs_lib_ctx_stash_sanitized_arg of the file base/gslibctx.c. The manipulation leads to improper removal of sensitive information before storage or transfer.
This vulnerability is traded as CVE-2025-48708. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-4945 | GNOME libsoup Cookie Expiration Date integer overflow (EUVD-2025-16034 / Nessus ID 237944)
2 months ago
A vulnerability classified as critical has been found in GNOME libsoup. This affects an unknown part of the component Cookie Expiration Date Handler. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2025-4945. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5847 | Tenda AC9 15.03.02.13 HTTP POST Request /goform/SetRemoteWebCfg formSetSafeWanWebMan remoteIp stack-based overflow (EUVD-2025-17397)
2 months ago
A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow.
This vulnerability is known as CVE-2025-5847. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2004-1567 | Silent Storm Portal 2.1 profile.php mail cross site scripting (EDB-565 / Nessus ID 15403)
2 months ago
A vulnerability was found in Silent Storm Portal 2.1 and classified as problematic. This issue affects some unknown processing of the file profile.php. The manipulation of the argument mail leads to basic cross site scripting.
The identification of this vulnerability is CVE-2004-1567. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-2873 | SpamAssassin up to 3.2.1 symlink (Nessus ID 67521 / ID 117522)
2 months ago
A vulnerability classified as problematic was found in SpamAssassin up to 3.2.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to symlink following.
This vulnerability is known as CVE-2007-2873. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-2882 | Sun Solaris 8.0/9.0/10.0 NFS Client Module denial of service (Nessus ID 22507 / ID 115561)
2 months ago
A vulnerability classified as problematic was found in Sun Solaris 8.0/9.0/10.0. Affected by this vulnerability is an unknown functionality of the component NFS Client Module. The manipulation leads to denial of service.
This vulnerability is known as CVE-2007-2882. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-2888 | Ezb Systems UltraISO 8.6.2.2011 stack-based overflow (EDB-3978 / ID 121502)
2 months ago
A vulnerability was found in Ezb Systems UltraISO 8.6.2.2011. It has been classified as very critical. Affected is an unknown function. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2007-2888. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-2903 | Microsoft Office 2000 ActiveX Control ouactrl.ocx first memory corruption (EDB-3973 / ID 110180)
2 months ago
A vulnerability, which was classified as critical, has been found in Microsoft Office 2000. Affected by this issue is some unknown functionality of the file ouactrl.ocx of the component ActiveX Control. The manipulation of the argument first leads to memory corruption.
This vulnerability is handled as CVE-2007-2903. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-2897 | Microsoft IIS up to 5.1 memory corruption (EDB-3965 / Nessus ID 64589)
2 months ago
A vulnerability was found in Microsoft IIS up to 5.1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2007-2897. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-2919 | E-Book Systems FlipViewer 4.0 ActiveX Control flipviewerx.dll stack-based overflow (VU#449089 / Nessus ID 25442)
2 months ago
A vulnerability was found in E-Book Systems FlipViewer 4.0 and classified as very critical. Affected by this issue is some unknown functionality in the library flipviewerx.dll of the component ActiveX Control. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2007-2919. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-2188 | Eejj33 BlackBook 1.0 footer.php cross site scripting (EDB-31721 / XFDB-42147)
2 months ago
A vulnerability, which was classified as problematic, was found in Eejj33 BlackBook 1.0. Affected is an unknown function of the file footer.php. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2008-2188. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-2931 | Microsoft MSN Messenger 7.0 memory corruption (VU#166521 / EDB-30537)
2 months ago
A vulnerability, which was classified as very critical, was found in Microsoft MSN Messenger 7.0. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2007-2931. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2007-2930 | ISC BIND 8.4.7 DNS Cache (VU#927905 / EDB-30535)
2 months ago
A vulnerability, which was classified as problematic, was found in ISC BIND 8.4.7. This affects an unknown part of the component DNS Cache. The manipulation leads to an unknown weakness.
This vulnerability is uniquely identified as CVE-2007-2930. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-2952 | Blue Coat Systems filter service 3.2.32 Administration Interface k9filter.exe memory corruption (ID 115879 / XFDB-44124)
2 months ago
A vulnerability was found in Blue Coat Systems filter service 3.2.32. It has been rated as very critical. This issue affects some unknown processing of the file k9filter.exe of the component Administration Interface. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2007-2952. The attack may be initiated remotely. There is no exploit available.
vuldb.com
OffensiveCon25 – Skin In The Game: Survival Of GPU IOMMU Irregular Damage
2 months ago
Authors/Presenters: Fish and Ling Hanqin
Our sincere appreciation to OffensiveCon by Binary Gecko, and the Presenters/Authors for publishing their outstanding OffensiveCon 2025 video content. Originating from the conference’s events located at the Hilton Berlin; and via the organizations YouTube channel.
Thanks and a Tip O' The Hat to Verification Labs :: Penetration Testing Specialists :: Trey Blalock GCTI, GWAPT, GCFA, GPEN, GPCS, GCPN, CRISC, CISA, CISM, CISSP, SSCP, CDPSE for recommending the OffensiveCon 25 conference.
The post OffensiveCon25 – Skin In The Game: Survival Of GPU IOMMU Irregular Damage appeared first on Security Boulevard.
Marc Handelman
CVE-2024-45199 | insightsoftware Hive JDBC up to 2.6.13 JDBC Driver injection (EUVD-2025-9897)
2 months ago
A vulnerability, which was classified as problematic, has been found in insightsoftware Hive JDBC up to 2.6.13. Affected by this issue is some unknown functionality of the component JDBC Driver. The manipulation leads to injection.
This vulnerability is handled as CVE-2024-45199. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47212 | Snowplow Iglu up to 0.13.0 API Endpoint denial of service (EUVD-2025-9896)
2 months ago
A vulnerability, which was classified as problematic, was found in Snowplow Iglu up to 0.13.0. This affects an unknown part of the component API Endpoint. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-47212. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-45198 | insightsoftware Spark JDBC 2.6.21 JDBC Driver injection (EUVD-2025-9898)
2 months ago
A vulnerability has been found in insightsoftware Spark JDBC 2.6.21 and classified as problematic. This vulnerability affects unknown code of the component JDBC Driver. The manipulation leads to injection.
This vulnerability was named CVE-2024-45198. The attack can be initiated remotely. There is no exploit available.
vuldb.com