Aggregator
CVE-2024-9328 | SourceCodester Advocate Office Management System 1.0 /control/edit_client.php id sql injection
9 months 3 weeks ago
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /control/edit_client.php. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2024-9328. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
AI 机器人能以 100% 成功率破解图像识别 CAPTCHA
9 months 3 weeks ago
苏黎世联邦理工学院研究人员报告,利用特别训练过的图像识别模型,AI 机器人能以 100% 成功率破解 ReCAPTCHA v2。Google 的 reCAPTCHA v2 会展示一组街景网格,要求用户识别哪些图像包含自行车、人行横道、楼梯或交通信号灯。Google 已经逐步淘汰 reCAPTCHA v2 改用 reCAPTCHA v3,通过分析用户交互识别人和机器人,不再需要用户接受繁琐的挑战。然而互联网上仍然有数百万个网站使用 reCAPTCHA v2,而使用 reCAPTCHA v3 的网站还会将 reCAPTCHA v2 作为后备方案。研究人员利用了开源模型 YOLO ("You Only Look Once") 的微调版本。他们表示在成功率达到 100% 之后我们正进入后 reCAPTCHA 时代。
Submit #415695: sourcecodester Advocate office management system 1.0 SQL Injection [Accepted]
9 months 3 weeks ago
Submit #415695 / VDB-278837
peanut886886
CVE-2021-47393 | Linux Kernel up to 4.19.208/5.4.150/5.10.70/5.14.9 hwmon thermal_cooling_device_stats_update out-of-bounds (Nessus ID 207773)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 4.19.208/5.4.150/5.10.70/5.14.9 and classified as problematic. Affected by this issue is the function thermal_cooling_device_stats_update of the component hwmon. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2021-47393. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47383 | Linux Kernel up to 5.14.9 tty vc_resize out-of-bounds (Nessus ID 207773)
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.14.9. This affects the function vc_resize of the component tty. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2021-47383. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41090 | Linux Kernel up to 6.10.1 Header Length tap_get_user_xdp out-of-bounds (Nessus ID 207773)
9 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 6.10.1 and classified as problematic. Affected by this vulnerability is the function tap_get_user_xdp of the component Header Length Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-41090. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41091 | Linux Kernel up to 6.10.1 Header Length tun_xdp_one out-of-bounds (Nessus ID 207773)
9 months 3 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.10.1. Affected by this vulnerability is the function tun_xdp_one of the component Header Length Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-41091. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40931 | Linux Kernel up to 5.10.220/5.15.161/6.1.94/6.6.34/6.9.5 mptcp snd_una uninitialized pointer (Nessus ID 207773)
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.10.220/5.15.161/6.1.94/6.6.34/6.9.5. Affected is the function snd_una of the component mptcp. The manipulation leads to uninitialized pointer.
This vulnerability is traded as CVE-2024-40931. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41064 | Linux Kernel up to 6.9.10 powerpc eeh_pe_report_edev denial of service (Nessus ID 207773)
9 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 6.9.10 and classified as critical. This vulnerability affects the function eeh_pe_report_edev of the component powerpc. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-41064. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47527 | Linux Kernel up to 5.15.6 tty_port_close memory leak (Nessus ID 207773)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 5.15.6 and classified as critical. Affected by this issue is the function tty_port_close. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2021-47527. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Meow
9 months 3 weeks ago
cohenido
Meow
9 months 3 weeks ago
cohenido
CVE-2007-4255 | PHP 5.2.3 msql_connect first memory corruption (EDB-4260 / Nessus ID 25971)
9 months 3 weeks ago
A vulnerability has been found in PHP 5.2.3 and classified as critical. This vulnerability affects the function msql_connect. The manipulation of the argument first leads to memory corruption.
This vulnerability was named CVE-2007-4255. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
由403所发现的SSRF高危漏洞
9 months 3 weeks ago
CVE-2007-4254 | Microsoft Visual Studio 6.0 ActiveX Control vdt70.dll NotSafe stack-based overflow (EDB-4259 / OSVDB-41080)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Visual Studio 6.0. This affects the function NotSafe in the library vdt70.dll of the component ActiveX Control. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2007-4254. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-7077 | gcefcu Gulf Coast Educators FCU 1.0.27 X.509 Certificate cryptographic issues (VU#582497)
9 months 3 weeks ago
A vulnerability classified as critical has been found in gcefcu Gulf Coast Educators FCU 1.0.27. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7077. The attack can only be done within the local network. There is no exploit available.
vuldb.com
Israel army hacked the communication network of the Beirut Airport control tower
9 months 3 weeks ago
Israel allegedly hacked Beirut airport ‘s control tower, warning an Iranian plane not to land, forcing it to return to Tehran. The Israeli cyber army on Saturday hacked into the control tower of Beirut Airport, the Rafic Hariri International Airport. The IDF breached the communication network of the control tower and threatened an Iranian civilian […]
Pierluigi Paganini
USENIX NSDI ’24 – The Bedrock of Byzantine Fault Tolerance: A Unified Platform for BFT Protocols Analysis, Implementation, and Experimentation
9 months 3 weeks ago
Outstanding Paper Award Winner!
Authors/Presenters:Mohammad Javad Amiri, Chenyuan Wu, Divyakant Agrawal, Amr El Abbadi, Boon Thau Loo, Mohammad Sadoghi
Our sincere thanks to USENIX, and the Presenters & Authors for publishing their superb 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI '24) content, placing the organizations enduring commitment to Open Access front and center. Originating from the conference’s events situated at the Hyatt Regency Santa Clara; and via the organizations YouTube channel.
The post USENIX NSDI ’24 – The Bedrock of Byzantine Fault Tolerance: A Unified Platform for BFT Protocols Analysis, Implementation, and Experimentation appeared first on Security Boulevard.
Marc Handelman
CVE-2021-36380 | Sunhillo SureLine up to 8.7.0.1.0 /cgi/networkDiag.cgi ipAddr/dnsAddr os command injection
9 months 3 weeks ago
A vulnerability was found in Sunhillo SureLine up to 8.7.0.1.0. It has been rated as critical. This issue affects some unknown processing of the file /cgi/networkDiag.cgi. The manipulation of the argument ipAddr/dnsAddr leads to os command injection.
The identification of this vulnerability is CVE-2021-36380. The attack can only be done within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com