Aggregator
CVE-2015-0060 | Microsoft Windows up to Vista Font Mapper win32k.sys input validation (MS15-010 / EDB-37098)
8 months 3 weeks ago
A vulnerability was found in Microsoft Windows up to Vista. It has been classified as critical. This affects an unknown part of the file win32k.sys of the component Font Mapper. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2015-0060. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-14312 | Aptana Jaxer 1.0.3.4547 Source Code Viewer index.html filename path traversal (ID 153985 / EDB-47214)
8 months 3 weeks ago
A vulnerability classified as problematic was found in Aptana Jaxer 1.0.3.4547. Affected by this vulnerability is an unknown functionality of the file tools/sourceViewer/index.html of the component Source Code Viewer. The manipulation of the argument filename with the input ../ leads to path traversal.
This vulnerability is known as CVE-2019-14312. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2015-0096 | Microsoft Windows Server 2003 SP2 up to Server 2012 R2 DLL data processing (MS15-020 / EDB-14403)
8 months 3 weeks ago
A vulnerability was found in Microsoft Windows. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to data processing error.
This vulnerability is uniquely identified as CVE-2015-0096. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Появился на 20 минут, написал Minecraft и исчез — революция в мире ИИ
8 months 3 weeks ago
Это был Kingfall от Google — и он уже успел стать легендой.
CVE-2024-25501 | WinMail up to 5.1/7.1 email cross site scripting (EUVD-2024-22829)
8 months 3 weeks ago
A vulnerability classified as problematic has been found in WinMail up to 5.1/7.1. This affects an unknown part. The manipulation of the argument email leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-25501. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-25454 | Axiomatic Bento4 1.6.0-640 Test null pointer dereference (Issue 875 / EUVD-2024-22783)
8 months 3 weeks ago
A vulnerability classified as problematic was found in Axiomatic Bento4 1.6.0-640. This vulnerability affects the function AP4_DescriptorFinder::Test. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-25454. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-25436 | pkp ojs 3.3 Production Module subject cross site scripting (EUVD-2024-22765)
8 months 3 weeks ago
A vulnerability classified as problematic was found in pkp ojs 3.3. This vulnerability affects unknown code of the component Production Module. The manipulation of the argument subject leads to cross site scripting.
This vulnerability was named CVE-2024-25436. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-25468 | Totolink X5000R 9.1.0u.6369_B20230113 NTPSyncWithHost host_time denial of service (EUVD-2024-22796)
8 months 3 weeks ago
A vulnerability was found in Totolink X5000R 9.1.0u.6369_B20230113 and classified as critical. Affected by this issue is the function NTPSyncWithHost. The manipulation of the argument host_time leads to denial of service.
This vulnerability is handled as CVE-2024-25468. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-25428 | MRCMS 3.1.2 Status sql injection (Issue 19 / EUVD-2024-22757)
8 months 3 weeks ago
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Status leads to sql injection.
This vulnerability is known as CVE-2024-25428. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-25435 | Md1health Md1patient 2.0.0 Msg cross site scripting (EUVD-2024-22764)
8 months 3 weeks ago
A vulnerability was found in Md1health Md1patient 2.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Msg leads to cross site scripting.
This vulnerability is handled as CVE-2024-25435. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-25422 | SEMCMS 4.8 SEMCMS_Menu.php information disclosure (EUVD-2024-22751)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in SEMCMS 4.8. Affected by this issue is some unknown functionality of the file SEMCMS_Menu.php. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-25422. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2011-3658 | Mozilla Firefox 8.0 SVG Element DOMAttrModified resource management (EDB-18847 / Nessus ID 74515)
8 months 3 weeks ago
A vulnerability has been found in Mozilla Firefox 8.0 and classified as critical. Affected by this vulnerability is the function DOMAttrModified of the component SVG Element Handler. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2011-3658. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5857 | code-projects Patient Record Management System 1.0 /urinalysis_record.php itr_no sql injection (EUVD-2025-17423)
8 months 3 weeks ago
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysis_record.php. The manipulation of the argument itr_no leads to sql injection.
The identification of this vulnerability is CVE-2025-5857. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5858 | PHPGurukul Nipah Virus Testing Management System 1.0 /patient-report.php searchdata sql injection (EUVD-2025-17422)
8 months 3 weeks ago
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /patient-report.php. The manipulation of the argument searchdata leads to sql injection.
This vulnerability is traded as CVE-2025-5858. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
东北大学 | Untangle: 多层 Web 服务器指纹识别
8 months 3 weeks ago
本文提出了一种多层 Web 服务器指纹识别方法,通过利用 HTTP 处理差异,实现了对三层结构的精准指纹识别。
Enterprise SIEMs miss 79% of known MITRE ATT&CK techniques
8 months 3 weeks ago
Using the MITRE ATT&CK framework as a baseline, organizations are generally improving year-over-year in understanding security information and event management (SIEM) detection coverage and quality, but plenty of room for improvement remains, according to CardinalOps. MITRE ATT&CK enhances SOC visibility Founded in 2013, the framework’s underlying goal remains unchanged–to help defenders align their defenses and prepare to detect and prevent a wide range of tactics, techniques, and procedures (TTPs) observed in real-life attack scenarios. Mapping … More →
The post Enterprise SIEMs miss 79% of known MITRE ATT&CK techniques appeared first on Help Net Security.
Help Net Security
CVE-2007-1241 | Audins Audiens 3.3 setup.php PATH_INFO cross site scripting (EDB-29677 / XFDB-32839)
8 months 3 weeks ago
A vulnerability was found in Audins Audiens 3.3 and classified as problematic. This issue affects some unknown processing of the file setup.php. The manipulation of the argument PATH_INFO leads to basic cross site scripting.
The identification of this vulnerability is CVE-2007-1241. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
抖音生活服务反爬专项!奖金1000元起步!
8 months 3 weeks ago
CVE-2024-25413 | FireBear Improved Import and Export 3.8.6 XSLT injection (ID 175801 / EUVD-2024-22744)
8 months 3 weeks ago
A vulnerability was found in FireBear Improved Import and Export 3.8.6. It has been classified as problematic. This affects an unknown part of the component XSLT Handler. The manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2024-25413. The attack needs to be done within the local network. There is no exploit available.
vuldb.com