Aggregator
CVE-2019-0227 | Oracle Policy Automation Connector for Siebel 10.4.6 Apache Axis server-side request forgery (EDB-46682)
3 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Oracle Policy Automation Connector for Siebel 10.4.6. Affected is an unknown function of the component Apache Axis. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2019-0227. The attack needs to be approached within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
警惕虚假 PDFCandy 网站骗局,恶意软件窃取用户敏感信息
3 months 3 weeks ago
安全客
CVE-2011-2462 | Adobe Acrobat Reader up to 9.0 memory corruption (RHSA-2012:0011 / EDB-18366)
3 months 3 weeks ago
A vulnerability was found in Adobe Acrobat Reader up to 9.0. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2011-2462. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Landmacht gereed voor moderne oorlogsvoering
3 months 3 weeks ago
Met 1.800 voertuigen, 200 drones en 4.500 militairen uit 3 landen razendsnel naar de oostgrens voor een gevechtsoperatie. De landmacht trainde dit de afgelopen weken tijdens Bastion Lion. De denkbeeldige oostgrens lag daarbij in Duitsland. De oefening vormde een realistische voorbereiding op een grootschalig conflict en loopt vandaag af.
Microsoft Teams 新型恶意攻击:TypeLib 劫持恶意软件或引发安全风暴
3 months 3 weeks ago
安全客
关于今天pecl网站上的dll下载按钮消失的解决办法
3 months 3 weeks ago
去这里下载对应的pecl扩展windows版 windows.php.net – /downloa […]
杨龙
Ночь. Пустой перекрёсток. Один удар бампера — и два дрона уже пишут историю
3 months 3 weeks ago
Готовы к тому, что ваше такси сдаст вас полиции быстрее, чем включится сирена?
Startup Exaforce Nabs $75M to Grow AI-Powered SOC Automation
3 months 3 weeks ago
Exaforce's AI-Powered Automation Aims to Streamline Security Ops for Enterprises
SOC automation startup Exaforce closed a $75 million in Series A financing round to enhance its AI model purpose-built for cybersecurity. The company plans to expand support for SaaS and cloud platforms and deploy agentic features to speed analyst workflows.
SOC automation startup Exaforce closed a $75 million in Series A financing round to enhance its AI model purpose-built for cybersecurity. The company plans to expand support for SaaS and cloud platforms and deploy agentic features to speed analyst workflows.
CTM360 Tracks Global Surge in SMS-Based Reward and Toll Scams
3 months 3 weeks ago
Thousands tricked by fake reward & toll scam texts. CTM360 exposes PointyPhish & TollShark—SMS phishing campaigns powered by the Darcula PhaaS platform, with 5K+ domains stealing payment info worldwide. [...]
Sponsored by CTM360
Startup Exaforce Nabs $75M to Grow AI-Powered SOC Automation
3 months 3 weeks ago
Exaforce's AI-Powered Automation Aims to Streamline Security Ops for Enterprises
SOC automation startup Exaforce closed a $75 million in Series A financing round to enhance its AI model purpose-built for cybersecurity. The company plans to expand support for SaaS and cloud platforms and deploy agentic features to speed analyst workflows.
SOC automation startup Exaforce closed a $75 million in Series A financing round to enhance its AI model purpose-built for cybersecurity. The company plans to expand support for SaaS and cloud platforms and deploy agentic features to speed analyst workflows.
Cybersecurity by Design: When Humans Meet Technology
3 months 3 weeks ago
If security tools are challenging to use, people will look for workarounds to get around the restrictions.
Matthew Warner
10 000 лет до краха цивилизации: людям осталось жить совсем недолго?
3 months 3 weeks ago
Генри Джи предсказал дату нашего исчезновения в новой книге. Есть ли шанс на спасение?
Один клик — и улитка внутри: как MysterySnail берёт госсистемы под контроль
3 months 3 weeks ago
Кибератаки затронули учреждения в России и Монголии — троянец маскируется под официальный документ.
Microsoft: Office 2016 and Office 2019 reach end of support in October
3 months 3 weeks ago
Microsoft has reminded customers that Office 2016 and Office 2019 will reach the end of extended support six months from now, on October 14, 2025. [...]
Sergiu Gatlan
CVE-2018-16840 | cURL up to 7.61.1 Easy Curl_close use after free (USN-3805-1 / Nessus ID 118591)
3 months 3 weeks ago
A vulnerability classified as critical was found in cURL up to 7.61.1. This vulnerability affects the function Curl_close of the component Easy Handler. The manipulation leads to use after free.
This vulnerability was named CVE-2018-16840. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-22955 | AudioCodes VoIP Desk Phone up to 3.4.4.1000 Firmware Image data authenticity (SYSS-2022-055)
3 months 3 weeks ago
A vulnerability was found in AudioCodes VoIP Desk Phone up to 3.4.4.1000. It has been classified as problematic. Affected is an unknown function of the component Firmware Image Handler. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is traded as CVE-2023-22955. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-54807 | Netgear WNR854T 1.5.2 UPNP Service addmap_exec NewInternalClient command injection
3 months 3 weeks ago
A vulnerability was found in Netgear WNR854T 1.5.2 and classified as critical. This issue affects the function addmap_exec of the component UPNP Service. The manipulation of the argument NewInternalClient leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-54807. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-54804 | Netgear WNR854T 1.5.2 Request post.cgi wan_hostname command injection
3 months 3 weeks ago
A vulnerability was found in Netgear WNR854T 1.5.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file post.cgi of the component Request Handler. The manipulation of the argument wan_hostname leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2024-54804. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54805 | Netgear WNR854T 1.5.2 Request post.cgi get_email command injection
3 months 3 weeks ago
A vulnerability was found in Netgear WNR854T 1.5.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file post.cgi of the component Request Handler. The manipulation of the argument get_email leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2024-54805. The attack may be launched remotely. There is no exploit available.
vuldb.com