Aggregator
CVE-2015-0235 | Apple Mac OS X up to 10.11.0 apache_mod_php memory corruption (HT205375 / EDB-35951)
6 months 2 weeks ago
A vulnerability was found in Apple Mac OS X up to 10.11.0. It has been classified as very critical. Affected is an unknown function of the component apache_mod_php. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2015-0235. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6826 | GitLab Community Edition/Enterprise Edition up to 17.3.5/17.4.2/17.5.0 XML Manifest File allocation of resources (Nessus ID 209628)
6 months 2 weeks ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 17.3.5/17.4.2/17.5.0 and classified as critical. Affected by this issue is some unknown functionality of the component XML Manifest File Handler. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2024-6826. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Exploring the Transformative Potential of AI in Cybersecurity
6 months 2 weeks ago
By continuously learning from new data, ML models can adapt to evolving threat landscapes, making them invaluable in identifying zero-day vulnerabilities before they can be exploited.
The post Exploring the Transformative Potential of AI in Cybersecurity appeared first on Security Boulevard.
Gourav Nagar
UK Government Introduces New Data Governance Legislation
6 months 2 weeks ago
The Data (Use and Access) Bill governs digital verification services and the use of personal data in public services, and will revamp the Information Commissioner’s Office
Конец фрагментации: RVA23 становится единым языком для экосистемы RISC-V
6 months 2 weeks ago
Новый профиль позволит RISC-V конкурировать с существующими лидерами.
地平线上市,终于可以说说余凯的故事了
6 months 2 weeks ago
为什么一个厌恶风险的创业者,能把一个风险巨大的事情做成?
ISC Stormcast For Thursday, October 24th, 2024 https://isc.sans.edu/podcastdetail/9194, (Thu, Oct 24th)
6 months 2 weeks ago
ISC Stormcast For Thursday, October 24th, 2024 https://isc.sans.edu/podcastdetail/9194
Mastering Production-Ready AI with Elastic & Google Cloud
6 months 2 weeks ago
CVE-2002-0564 | Oracle9i 9.0/9.0.1 PL/SQL Module improper authentication (VU#193523 / Nessus ID 57619)
6 months 2 weeks ago
A vulnerability was found in Oracle9i 9.0/9.0.1. It has been classified as critical. Affected is an unknown function of the component PL/SQL Module. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2002-0564. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Lazarus Group Exploits Google Chrome Vulnerability to Control Infected Devices
6 months 2 weeks ago
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a now-patched security flaw in Google Chrome to seize control of infected devices.
Cybersecurity vendor Kaspersky said it made the discovery after it came across a novel attack chain in May 2024 that targeted the personal computer of an unnamed Russian national with the Manuscrypt backdoor.
The Hacker News
关于VMware vCenter Server存在堆溢出漏洞的安全公告
6 months 2 weeks ago
2024年10月23日,国家信息安全漏洞共享平台(CNVD)收录了VMware vCenter Server堆溢出漏洞(CNVD-2024-41447,对应CVE-2024-38812)。
CVE-2002-0562 | Oracle9i 9.0/9.0.1 JSP global.jsa Password information disclosure (VU#698467 / Nessus ID 10850)
6 months 2 weeks ago
A vulnerability has been found in Oracle9i 9.0/9.0.1 and classified as critical. This vulnerability affects unknown code of the file global.jsa of the component JSP Handler. The manipulation leads to information disclosure (Password).
This vulnerability was named CVE-2002-0562. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2003-1092 | Christos Zoulas File up to 3.40 Automatic File Content Type Recognition memory corruption (EDB-22326 / Nessus ID 13787)
6 months 2 weeks ago
A vulnerability has been found in Christos Zoulas File up to 3.40 and classified as critical. This vulnerability affects unknown code of the component Automatic File Content Type Recognition. The manipulation leads to memory corruption.
This vulnerability was named CVE-2003-1092. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8667 | HurryTimer Plugin up to 2.10.0 on WordPress authorization
6 months 2 weeks ago
A vulnerability was found in HurryTimer Plugin up to 2.10.0 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-8667. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10050 | Elementor Header & Footer Builder Plugin up to 1.6.43 on WordPress Shortcode information disclosure
6 months 2 weeks ago
A vulnerability was found in Elementor Header & Footer Builder Plugin up to 1.6.43 on WordPress. It has been classified as problematic. This affects an unknown part of the component Shortcode Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-10050. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9531 | MultiVendorX Plugin up to 4.2.4 on WordPress authorization
6 months 2 weeks ago
A vulnerability was found in MultiVendorX Plugin up to 4.2.4 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-9531. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9943 | MultiVendorX Plugin up to 4.2.4 on WordPress cross-site request forgery
6 months 2 weeks ago
A vulnerability was found in MultiVendorX Plugin up to 4.2.4 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-9943. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8717 | PDF Flipbook, 3D Flipbook, PDF Embed, PDF Viewer Plugin cross site scripting
6 months 2 weeks ago
A vulnerability classified as problematic has been found in PDF Flipbook, 3D Flipbook, PDF Embed, PDF Viewer Plugin up to 2.3.32 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-8717. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Cybersecurity Teams Largely Ignored in AI Policy Development
6 months 2 weeks ago
A new ISACA study has revealed that cybersecurity professionals are often overlooked in the development of AI policies