Aggregator
最后一天福利 | 2024年度WebShell专题、内存马技术、反序列化漏洞文章和工具汇总
10 months 1 week ago
Honeyscanner – A vulnerability analyzer for Honeypots
10 months 1 week ago
Honeyscanner – A vulnerability analyzer for Honeypots Honeyscanner is a vulnerability analyzer for honeypots designed to automatically attack a given honeypot, in order to determine if the honeypot is vulnerable to specific types of...
The post Honeyscanner – A vulnerability analyzer for Honeypots appeared first on Penetration Testing Tools.
ddos
Reaper: PoC designed to exploit BYOVD driver vulnerability
10 months 1 week ago
Reaper Reaper is a proof-of-concept designed to exploit BYOVD (Bring Your Own Vulnerable Driver) driver vulnerability. This malicious technique involves inserting a legitimate, vulnerable driver into a target system, which allows attackers to exploit...
The post Reaper: PoC designed to exploit BYOVD driver vulnerability appeared first on Penetration Testing Tools.
ddos
大年初七 | 祥蛇送安,前程“巳”锦
10 months 1 week ago
新春启智,驱动创新
Everest
10 months 1 week ago
cohenido
Everest
10 months 1 week ago
cohenido
Daily Dose of Dark Web Informer - February 2nd, 2025
10 months 1 week ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-20317 | Cisco IOS XR up to 7.10.1 Ethernet Frame incorrect provision of specified functionality (cisco-sa-l2services-2mvHdNuC / Nessus ID 214885)
10 months 1 week ago
A vulnerability was found in Cisco IOS XR up to 7.10.1. It has been classified as critical. Affected is an unknown function of the component Ethernet Frame Handler. The manipulation leads to incorrect provision of specified functionality.
This vulnerability is traded as CVE-2024-20317. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20390 | Cisco IOS XR up to 24.2.1 Dedicated XML Agent verification of source (cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S / Nessus ID 214884)
10 months 1 week ago
A vulnerability was found in Cisco IOS XR and classified as problematic. This issue affects some unknown processing of the component Dedicated XML Agent. The manipulation leads to improper verification of source of a communication channel.
The identification of this vulnerability is CVE-2024-20390. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56669 | Linux Kernel up to 6.12.5 cache_tag_unassign_domain null pointer dereference (Nessus ID 214888)
10 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.12.5. It has been declared as critical. Affected by this vulnerability is the function cache_tag_unassign_domain. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-56669. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52526 | Linux Kernel up to 6.1.56/6.5.6 erofs memory leak (6a5a8f0a9740/c955751cbf86/75a5221630fe / Nessus ID 214888)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.56/6.5.6. This issue affects some unknown processing of the component erofs. The manipulation leads to memory leak.
The identification of this vulnerability is CVE-2023-52526. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-20197 | ClamAV Antivirus HFS+ File Scanning denial of service (cisco-sa-clamav-rNwNEEee / Nessus ID 214890)
10 months 1 week ago
A vulnerability was found in ClamAV Antivirus. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component HFS+ File Scanning. The manipulation leads to denial of service.
This vulnerability is known as CVE-2023-20197. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-49897 | FXC AE1021PE/AE1021 up to 2.0.9 os command injection
10 months 1 week ago
A vulnerability classified as critical has been found in FXC AE1021PE and AE1021 up to 2.0.9. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2023-49897. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-7024 | Google Chrome up to 120.0.6099.109 WebRTC NA heap-based overflow (FEDORA-2023-1de2fe25c4)
10 months 1 week ago
A vulnerability classified as critical has been found in Google Chrome. Affected is an unknown function of the component WebRTC. The manipulation of the argument NA leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2023-7024. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48630 | Linux Kernel up to 4.19.244/5.4.195/5.10.117/5.15.41/5.17.9 qcom-rng qcom_rng_read infinite loop
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 4.19.244/5.4.195/5.10.117/5.15.41/5.17.9. Affected by this issue is the function qcom_rng_read of the component qcom-rng. The manipulation leads to infinite loop.
This vulnerability is handled as CVE-2022-48630. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52583 | Linux Kernel up to 6.7.3 ceph dget deadlock
10 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.7.3. It has been declared as problematic. This vulnerability affects the function dget of the component ceph. The manipulation leads to deadlock.
This vulnerability was named CVE-2023-52583. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
小米股价创新高,市值突破万亿;披头士 「AI 歌曲」获格莱美大奖;《流浪地球 3》三月开机,开招演员|极客早知道
10 months 1 week ago
小米集团股价今日突破 39 港元再创新高,市值达 10000 亿港元;披头士乐队(The Beatles)凭借其 AI 辅助制作的歌曲《Now and Then》赢得了最佳摇滚表演奖;OpenAI 表示正在考虑「不同的开源战略」。
Google fixed actively exploited kernel zero-day flaw
10 months 1 week ago
The February 2025 Android security updates addressed 48 vulnerabilities, including a kernel zero-day flaw exploited in the wild. The February 2025 Android security updates addressed 48 vulnerabilities, including a zero-day flaw, tracked as CVE-2024-53104, which is actively exploited in attacks in the wild. “There are indications that CVE-2024-53104 may be under limited, targeted exploitation.” reads Google’s […]
Pierluigi Paganini
First Apple-notarized porn app available to iPhone users in Europe
10 months 1 week ago
The first Apple-notarized porn app, "Hot Tub," is now available to iPhone users in Europe through the alternative app marketplace, AltStore PAL. [...]
Lawrence Abrams