Aggregator
ChatGPT в мире без правил: хакер заставил ИИ поделиться рецептом взрывчатки
9 months 3 weeks ago
Чтобы обмануть чат-бота, нужно мыслить, как чат-бот.
CVE-2024-46748 | Linux Kernel up to 6.10.9 MAX_RW_COUNT Privilege Escalation (cec226f9b1fd/51d37982bbac)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been declared as problematic. This vulnerability affects the function MAX_RW_COUNT. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2024-46748. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46748 | Linux Kernel up to 6.10.9 MAX_RW_COUNT Privilege Escalation (cec226f9b1fd/51d37982bbac)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been declared as problematic. This vulnerability affects the function MAX_RW_COUNT. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2024-46748. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46747 | Linux Kernel up to 6.10.9 cougar_report_fixup out-of-bounds
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.9 and classified as problematic. Affected by this issue is the function cougar_report_fixup. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-46747. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
新版AGESA大幅度降低RYZEN 9000系列延迟 从180纳秒降低至75纳秒
9 months 3 weeks ago
CVE-2024-46800 | Linux Kernel up to 6.10.9 netem_dequeue use after free
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been classified as critical. This affects the function netem_dequeue. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-46800. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46749 | Linux Kernel up to 6.6.50/6.10.9 Bluetooth btnxpuart_flush null pointer dereference (013dae4735d2/056e0cd381d5/c68bbf5e334b)
9 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 6.6.50/6.10.9 and classified as critical. Affected by this vulnerability is the function btnxpuart_flush of the component Bluetooth. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-46749. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46747 | Linux Kernel up to 6.10.9 cougar_report_fixup out-of-bounds
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.9 and classified as problematic. Affected by this issue is the function cougar_report_fixup. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-46747. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46774 | Linux Kernel up to 6.10.9 Speculative Execution sys_rtas stack-based overflow (68d815648094/0974d03eb479)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.10.9. Affected is the function sys_rtas of the component Speculative Execution. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2024-46774. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46743 | Linux Kernel up to 6.10.9 of_irq_parse_raw out-of-bounds
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.10.9. This issue affects the function of_irq_parse_raw. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-46743. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46750 | Linux Kernel up to 6.10.9 drivers/pci/pci.c pci_bus_lock deadlock
9 months 3 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.10.9. This vulnerability affects the function pci_bus_lock of the file drivers/pci/pci.c. The manipulation leads to deadlock.
This vulnerability was named CVE-2024-46750. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46754 | Linux Kernel up to 6.10.9 bpf_test_run state issue (9cd15511de7c/c13fda93aca1)
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.10.9. This affects the function bpf_test_run. The manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2024-46754. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46801 | Linux Kernel up to 6.10.9 libfs get_stashed_dentry null pointer dereference (03e2a1209a83/4e32c25b58b9)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been rated as critical. Affected by this issue is the function get_stashed_dentry of the component libfs. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-46801. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46798 | Linux Kernel up to 6.10.9 snd_pcm_suspend_all use after free
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been declared as critical. Affected by this vulnerability is the function snd_pcm_suspend_all. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-46798. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46797 | Linux Kernel up to 6.6.50/6.10.9 queued_spin_lock_slowpath initialization (d84ab6661e8d/f06af737e4be/734ad0af3609)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.50/6.10.9. It has been classified as problematic. Affected is the function queued_spin_lock_slowpath. The manipulation leads to improper initialization.
This vulnerability is traded as CVE-2024-46797. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46796 | Linux Kernel up to 6.6.50/6.10.9 SMB Client smb2_set_path_size use after free (5a72d1edb084/762099898309/f9c169b51b6c)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.50/6.10.9 and classified as critical. This issue affects the function smb2_set_path_size of the component SMB Client. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-46796. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware
9 months 3 weeks ago
A North Korea-linked cyber-espionage group has been observed leveraging job-themed phishing lures to target prospective victims in energy and aerospace verticals and infect them with a previously undocumented backdoor dubbed MISTPEN.
The activity cluster is being tracked by Google-owned Mandiant under the moniker UNC2970, which it said overlaps with a threat group known as TEMP.Hermit, which is
The Hacker News
PlainID introduces identity security for Zscaler
9 months 3 weeks ago
PlainID announces the PlainID Authorizer for Zscaler, available via PlainID SaaS Authorization Management, centralizes policy management for Zscaler and SaaS applications and tools. Zscaler and other SASE (Secure Access Service Edge) solutions have made significant strides in integrating identity-aware controls into their authorization frameworks – marking a crucial step forward. However, more can be done to address a critical gap. It’s imperative that any security enforcement point responsible for managing network connectivity must also align … More →
The post PlainID introduces identity security for Zscaler appeared first on Help Net Security.
Industry News
SCTF 2024|青春风暴 竞燃金秋
9 months 3 weeks ago
2024.09.28 09:00 - 09.30 09:00,SCTF 2024 即将启航