Aggregator
Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE
6 months 2 weeks ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Fortinet releases patches for publicly undisclosed critical FortiManager vulnerability In the last couple of days, Fortinet has released critical security updates for FortiManager, to fix a critical vulnerability that is reportedly being exploited by Chinese threat actors. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812) Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter … More →
The post Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE appeared first on Help Net Security.
Help Net Security
Handala
6 months 2 weeks ago
cohenido
Cyber Attack on Israel Volleyball Association Claimed by DarkRaaS
6 months 2 weeks ago
cohenido
CVE-2008-2684 | Black Ice Barcode SDK 5.01 ActiveX Control bidib.ocx code injection (EDB-5750 / XFDB-42896)
6 months 2 weeks ago
A vulnerability classified as very critical has been found in Black Ice Barcode SDK 5.01. Affected is an unknown function of the file bidib.ocx of the component ActiveX Control. The manipulation leads to code injection.
This vulnerability is traded as CVE-2008-2684. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2691 | JiRo FAQ Manager eXperience 1.0 read.asp fID sql injection (EDB-5753 / XFDB-42919)
6 months 2 weeks ago
A vulnerability was found in JiRo FAQ Manager eXperience 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file read.asp. The manipulation of the argument fID leads to sql injection.
This vulnerability is handled as CVE-2008-2691. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2694 | phpInv 0.8.0 search.php keyword cross site scripting (EDB-5754 / XFDB-42928)
6 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in phpInv 0.8.0. This issue affects some unknown processing of the file search.php. The manipulation of the argument keyword leads to cross site scripting.
The identification of this vulnerability is CVE-2008-2694. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2701 | Com Gameq up to 4.0 on Joomla index.php category_id sql injection (EDB-5752 / XFDB-42929)
6 months 2 weeks ago
A vulnerability classified as critical has been found in Com Gameq up to 4.0 on Joomla. Affected is an unknown function of the file index.php. The manipulation of the argument category_id leads to sql injection.
This vulnerability is traded as CVE-2008-2701. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2119 | Digium Asterisk up to 1.2.29 SIP input validation (EDB-5749 / Nessus ID 38677)
6 months 2 weeks ago
A vulnerability was found in Digium Asterisk up to 1.2.29. It has been classified as problematic. This affects an unknown part of the component SIP Handler. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2008-2119. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-2683 | Black Ice Barcode SDK 5.01 ActiveX Control bidib.ocx DownloadImageFileURL second input validation (EDB-17415 / XFDB-42891)
6 months 2 weeks ago
A vulnerability was found in Black Ice Barcode SDK 5.01. It has been rated as very critical. This issue affects the function DownloadImageFileURL of the file bidib.ocx of the component ActiveX Control. The manipulation of the argument second leads to improper input validation.
The identification of this vulnerability is CVE-2008-2683. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6068 | Web Design Hero JoomlaDate 1.2 index.php user sql injection (EDB-5748 / XFDB-42873)
6 months 2 weeks ago
A vulnerability classified as critical was found in Web Design Hero JoomlaDate 1.2. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument user leads to sql injection.
This vulnerability is known as CVE-2008-6068. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
雷军晒小米15发布会首次彩排合影;全华班 BLG 晋级S14决赛;阿里同意支付4.335亿美元和解美股集体诉讼案 | 极客早知道
6 months 2 weeks ago
消息称谷歌将推出「Project Jarvis」:可实现网页任务自动化;上汽荣威 D7 DMH 世界冠军版轿车下月初上市;腾讯研发全球首个大熊猫模型
CVE-2010-4250 | Linux Kernel 2.6.36.1/2.6.36.2/2.6.36.3/2.6.36.4 inotify_init1 resource management (RHSA-2011:0498 / EDB-35013)
6 months 2 weeks ago
A vulnerability classified as problematic was found in Linux Kernel 2.6.36.1/2.6.36.2/2.6.36.3/2.6.36.4. Affected by this vulnerability is the function inotify_init1. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2010-4250. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
RansomHub
6 months 2 weeks ago
cohenido
Технологии-2025: Gartner предсказывает технореволюцию
6 months 2 weeks ago
От квантовой криптографии до невидимого интеллекта в рабочей среде.
CVE-2017-2435 | Apple iOS up to 10.2 CoreText memory corruption (HT207617 / EDB-40961)
6 months 2 weeks ago
A vulnerability has been found in Apple iOS up to 10.2 and classified as critical. This vulnerability affects unknown code of the component CoreText. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2435. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-0116 | AWStats 6.3 aswtats.pl open configdir input validation (VU#272296 / EDB-772)
6 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in AWStats 6.3. Affected by this issue is the function open of the file aswtats.pl. The manipulation of the argument configdir leads to improper input validation.
This vulnerability is handled as CVE-2005-0116. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
RansomHub
6 months 2 weeks ago
cohenido
直观解读 JuiceFS 的数据和元数据设计(一):看山是山(2024)
6 months 2 weeks ago
Published at 2024-10-27 | Last Update 2024-10-27 本系列分为三篇文章,试图通过简单的实地环境来直观理解 JuiceFS的数
直观解读 JuiceFS 的数据和元数据设计(二):看山不是山(2024)
6 months 2 weeks ago
Published at 2024-10-27 | Last Update 2024-10-27 本系列分为三篇文章,试图通过简单的实地环境来直观理解 JuiceFS的数