Aggregator
.NET内网实战:.NET 红队通过 SharpZipLib 批量压缩打包文件
7 months 2 weeks ago
特斯拉首次完成全自动驾驶交付;YU7 锁单交付时间更新,标准版最快 53 周;OpenAI 首次采用谷歌芯片训练 | 极客早知道
7 months 2 weeks ago
苹果 3.5 亿美元买下湾区两栋写字楼,位于总部 11 公里外
高德地图被曝提供逆行导航路线,回应称仅作展示用途并强化警示
德国要求苹果与谷歌下架 DeepSeek 应用
Could someone please help
7 months 2 weeks ago
一个开放的黑客社区,帮助新手成长为老手,提供问答学习平台,并邀请加入Discord。
CVE-2025-53393 | Akka up to 2.10.6 Cluster Metrics deserialization (EUVD-2025-19463)
7 months 2 weeks ago
A vulnerability was found in Akka up to 2.10.6. It has been declared as problematic. This vulnerability affects unknown code of the component Cluster Metrics Handler. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-53393. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-53391 | Debian zulucrypt up to 6.2.0-1 PolicyKit CMakeLists.txt authorization (EUVD-2025-19461)
7 months 2 weeks ago
A vulnerability was found in Debian zulucrypt up to 6.2.0-1. It has been classified as critical. This affects an unknown part of the file zuluPolkit/CMakeLists.txt of the component PolicyKit. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-53391. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-53392 | Netgate pfSense CE 2.8.0 diag_command.php dlPath absolute path traversal (EUVD-2025-19534)
7 months 2 weeks ago
A vulnerability was found in Netgate pfSense CE 2.8.0 and classified as problematic. Affected by this issue is some unknown functionality of the file diag_command.php. The manipulation of the argument dlPath leads to absolute path traversal.
This vulnerability is handled as CVE-2025-53392. The attack may be launched remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
vuldb.com
Threat Actors Transform GIFTEDCROOK Stealer into an Intelligence-Gathering Tool
7 months 2 weeks ago
The Arctic Wolf Labs team has uncovered a dramatic transformation in the capabilities of the GIFTEDCROOK infostealer, wielded by the threat group UAC-0226. Initially identified as a rudimentary browser data stealer in early 2025, this malware has undergone rapid evolution through versions 1.2 and 1.3, morphing into a sophisticated intelligence-gathering tool by June 2025. This […]
The post Threat Actors Transform GIFTEDCROOK Stealer into an Intelligence-Gathering Tool appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2025-6825 | TOTOLINK A702R up to 4.0.0-B20230721.1521 HTTP POST Request /boafrm/formWlSiteSurvey submit-url buffer overflow
7 months 2 weeks ago
A vulnerability classified as critical was found in TOTOLINK A702R up to 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is known as CVE-2025-6825. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6826 | code-projects Payroll Management System 1.0 ajax.php?action=save_department ID sql injection
7 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in code-projects Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /Payroll_Management_System/ajax.php?action=save_department. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2025-6826. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2015-1730 | Microsoft Internet Explorer 9 JavaScriptStackWalker resource management (MS15-056 / EDB-40881)
7 months 2 weeks ago
A vulnerability was found in Microsoft Internet Explorer 9. It has been rated as critical. This issue affects the function JavaScriptStackWalker. The manipulation leads to improper resource management.
The identification of this vulnerability is CVE-2015-1730. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2009-2442 | Linea21 1.2.1 Search cross site scripting (EDB-34811 / SA35745)
7 months 2 weeks ago
A vulnerability was found in Linea21 1.2.1. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument Search leads to cross site scripting.
The identification of this vulnerability is CVE-2009-2442. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6824 | TOTOLINK X15 up to 1.0.0-B20230714.1105 HTTP POST Request formParentControl submit-url buffer overflow (EUVD-2025-19456)
7 months 2 weeks ago
A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is traded as CVE-2025-6824. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2005-3922 | Panda Titanium 2006 Antivirus pskcmp.dll heap-based overflow (ID 115309 / XFDB-23276)
7 months 2 weeks ago
A vulnerability was found in Panda Titanium 2006 Antivirus. It has been classified as critical. This affects an unknown part in the library pskcmp.dll. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2005-3922. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2005-3934 | Symantec pcAnywhere up to 11.5.1 on 32-bit Buffer denial of service (SYM05-026 / ID 115308)
7 months 2 weeks ago
A vulnerability was found in Symantec pcAnywhere up to 11.5.1 on 32-bit. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service (Buffer).
This vulnerability is uniquely identified as CVE-2005-3934. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-3921 | Cisco IOS up to 12 Cisco Discovery Protocol Logging cross site scripting (Nessus ID 48991 / ID 12220)
7 months 2 weeks ago
A vulnerability was found in Cisco IOS up to 12. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Cisco Discovery Protocol Logging. The manipulation leads to basic cross site scripting.
This vulnerability is handled as CVE-2005-3921. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-3964 | Integrated Computer Solutions OpenMotif 2.2.3 uildiags.c open_source_file memory corruption (Nessus ID 20357 / ID 117718)
7 months 2 weeks ago
A vulnerability classified as critical has been found in Integrated Computer Solutions OpenMotif 2.2.3. This affects the function open_source_file of the file uildiags.c. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2005-3964. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-4178 | Matt Johnston Dropbear SSH Server up to 0.46 memory corruption (Nessus ID 22789 / ID 38507)
7 months 2 weeks ago
A vulnerability was found in Matt Johnston Dropbear SSH Server up to 0.46. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2005-4178. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-4158 | Todd Miller sudo up to 1.6.8 P9 Perl Environment Cleaner Remote Code Execution (EDB-27056 / Nessus ID 20465)
7 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Todd Miller sudo. Affected by this issue is some unknown functionality of the component Perl Environment Cleaner. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2005-4158. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-4272 | IBM AIX up to 5.3 L muxatmd memory corruption (Nessus ID 65268 / ID 115416)
7 months 2 weeks ago
A vulnerability was found in IBM AIX up to 5.3 L. It has been rated as very critical. This issue affects some unknown processing of the component muxatmd. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2005-4272. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com