Aggregator
OpenAI o1 - Questoinable Empathy
9 months 3 weeks ago
OpenAI o1 came out just in time for me to add it to my 2024 Q3 benchmarks on AI empathy (to be publi
RSTCON 2024 CTF (Online/Hybrid)
9 months 3 weeks ago
Name: RSTCON 2024 CTF (Online/Hybrid) (an RSTCON CTF event.)
Date: Sept. 13, 2024, 7:45 p.m. — 15 Sept. 2024, 16:45 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Savannah, Georgia, USA
Offical URL: https://metactf.com/join/rstcon24
Rating weight: 24.00
Event organizers: RSTCON
Date: Sept. 13, 2024, 7:45 p.m. — 15 Sept. 2024, 16:45 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Savannah, Georgia, USA
Offical URL: https://metactf.com/join/rstcon24
Rating weight: 24.00
Event organizers: RSTCON
TO DELETE - Event: https://ctftime.org/event/2520
9 months 3 weeks ago
Name: TO DELETE - Event: https://ctftime.org/event/2520 (an Securinets CTF event.)
Date: Sept. 14, 2024, 7 p.m. — 15 Sept. 2024, 19:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.securinets.tn/
Rating weight: 95.59
Event organizers: Securinets
Date: Sept. 14, 2024, 7 p.m. — 15 Sept. 2024, 19:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.securinets.tn/
Rating weight: 95.59
Event organizers: Securinets
CVE-2021-36741 | Trend Micro Apex One Management Console unrestricted upload
9 months 3 weeks ago
A vulnerability was found in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security. It has been rated as critical. This issue affects some unknown processing of the component Management Console Handler. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2021-36741. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-36942 | Microsoft Windows Server 20H2 up to Server 2016 LSA information disclosure
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Microsoft Windows. Affected is an unknown function of the component LSA. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2021-36942. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-35395 | Realtek Jungle SDK up to 3.4.14B HTTP Web Server url stack-based overflow
9 months 3 weeks ago
A vulnerability was found in Realtek Jungle SDK up to 3.4.14B and classified as critical. This issue affects some unknown processing of the component HTTP Web Server. The manipulation of the argument url leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2021-35395. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-36955 | Microsoft Windows up to Server 2022 Common Log File System Driver Privilege Escalation
9 months 3 weeks ago
A vulnerability classified as very critical has been found in Microsoft Windows. Affected is an unknown function of the component Common Log File System Driver. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2021-36955. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-38645 | Microsoft Azure Open Management Infrastructure Local Privilege Escalation
9 months 3 weeks ago
A vulnerability was found in Microsoft Azure Open Management Infrastructure and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to Local Privilege Escalation.
This vulnerability is handled as CVE-2021-38645. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-38000 | Google Chrome up to 95.0.4638.54 Intents redirect
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Google Chrome. Affected is an unknown function of the component Intents. The manipulation leads to open redirect.
This vulnerability is traded as CVE-2021-38000. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-38003 | Google Chrome up to 95.0.4638.54 V8 exceptional condition
9 months 3 weeks ago
A vulnerability was found in Google Chrome. It has been classified as critical. This affects an unknown part of the component V8. The manipulation leads to handling of exceptional conditions.
This vulnerability is uniquely identified as CVE-2021-38003. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-35464 | ForgeRock Access Management up to 6.5.3 Privilege Escalation (a47894244 / EDB-50131)
9 months 3 weeks ago
A vulnerability classified as critical has been found in ForgeRock Access Management up to 6.5.3. This affects an unknown part. The manipulation leads to Privilege Escalation.
This vulnerability is uniquely identified as CVE-2021-35464. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8875 | vedees wcms up to 0.3.2 /wex/finder.php path traversal
9 months 3 weeks ago
A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulation of the argument p leads to path traversal.
This vulnerability is known as CVE-2024-8875. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-8876 | xiaohe4966 TpMeCMS up to 1.3.3.1 /index/ajax/lang path traversal
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal.
This vulnerability is handled as CVE-2024-8876. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Discovering Human Factories: A Personal Reflection on Modern Work, AI, and Creativity
9 months 3 weeks ago
To write in public or not...Note: This piece is intentionally raw and unpolished, reflecting a direc
CVE-2014-6769 | mobilesoft Meteo Belgique 3.2 X.509 Certificate cryptographic issues (VU#582497)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in mobilesoft Meteo Belgique 3.2. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-6769. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2007-2755 | PrecisionID Barcode 1.9 ActiveX Control precisionid_barcode.dll savetofile privileges management (EDB-3938 / XFDB-34337)
9 months 3 weeks ago
A vulnerability was found in PrecisionID Barcode 1.9. It has been rated as very critical. This issue affects the function savetofile in the library precisionid_barcode.dll of the component ActiveX Control. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2007-2755. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-6768 | Anywhere Anytime Yoga Workout 1 X.509 Certificate cryptographic issues (VU#582497)
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Anywhere Anytime Yoga Workout 1. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-6768. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2014-4155 | ZTE ZXV10 W300 cross-site request forgery (ID 127129 / EDB-33803)
9 months 3 weeks ago
A vulnerability classified as critical was found in ZTE ZXV10 W300. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2014-4155. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-2447 | Apple iOS up to 10.2 WebKit Bound memory corruption (HT207617 / EDB-41743)
9 months 3 weeks ago
A vulnerability has been found in Apple iOS up to 10.2 and classified as problematic. This vulnerability affects the function Bound of the component WebKit. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2447. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com