Aggregator
以色列间谍软件公司Paragon涉嫌利用WhatsApp零点击漏洞发动攻击
10 months 2 weeks ago
WhatsApp披露以色列间谍软件公司Paragon利用零点击漏洞攻击90名用户,包括记者和民间社会成员,引发全球关注。
CVE-2025-24129 | Apple visionOS type confusion (Nessus ID 214659)
10 months 2 weeks ago
A vulnerability was found in Apple visionOS. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to type confusion.
This vulnerability was named CVE-2025-24129. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24129 | Apple tvOS type confusion (Nessus ID 214659)
10 months 2 weeks ago
A vulnerability was found in Apple tvOS. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to type confusion.
The identification of this vulnerability is CVE-2025-24129. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24129 | Apple macOS type confusion (Nessus ID 214659)
10 months 2 weeks ago
A vulnerability classified as problematic has been found in Apple macOS. Affected is an unknown function. The manipulation leads to type confusion.
This vulnerability is traded as CVE-2025-24129. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24129 | Apple watchOS type confusion (Nessus ID 214659)
10 months 2 weeks ago
A vulnerability classified as problematic was found in Apple watchOS. Affected by this vulnerability is an unknown functionality. The manipulation leads to type confusion.
This vulnerability is known as CVE-2025-24129. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24129 | Apple iOS/iPadOS type confusion (Nessus ID 214659)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Apple iOS and iPadOS. Affected by this issue is some unknown functionality. The manipulation leads to type confusion.
This vulnerability is handled as CVE-2025-24129. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57395 | Safety Production Process Management System 1.0 number information disclosure
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Safety Production Process Management System 1.0. Affected is an unknown function. The manipulation of the argument number leads to information disclosure.
This vulnerability is traded as CVE-2024-57395. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24152 | Apple macOS up to 15.2 Kernel Memory memory corruption (Nessus ID 214659)
10 months 2 weeks ago
A vulnerability classified as critical has been found in Apple macOS up to 15.2. This affects an unknown part of the component Kernel Memory Handler. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2025-24152. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
OpenAI Unveils o3-mini With Enhanced Coding, STEM Reasoning
10 months 2 weeks ago
OpenAI's New Cost-Efficient AI Reasoning Model Excels in Math, Coding, and Science
OpenAI has launched o3-mini, a high-performance AI model optimized for STEM tasks. The model offers enhanced reasoning abilities, reduced latency, and features like function calling and structured outputs. Available in ChatGPT and API, o3-mini surpasses its predecessor in coding and math accuracy.
OpenAI has launched o3-mini, a high-performance AI model optimized for STEM tasks. The model offers enhanced reasoning abilities, reduced latency, and features like function calling and structured outputs. Available in ChatGPT and API, o3-mini surpasses its predecessor in coding and math accuracy.
CVE-2024-28130 | OFFIS DCMTK 3.6.8 createFromImage type conversion (TALOS-2024-1957 / Nessus ID 214857)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in OFFIS DCMTK 3.6.8. This issue affects the function DVPSSoftcopyVOI_PList::createFromImage. The manipulation leads to incorrect type conversion.
The identification of this vulnerability is CVE-2024-28130. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-34509 | DCMTK up to 3.6.8 dcmdata memory corruption (Nessus ID 214857)
10 months 2 weeks ago
A vulnerability was found in DCMTK up to 3.6.8 and classified as critical. Affected by this issue is some unknown functionality of the component dcmdata. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2024-34509. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-2121 | OFFIS DCMTK up to 3.6.6 DICOM File null pointer dereference (icsma-22-174-01 / Nessus ID 214857)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in OFFIS DCMTK up to 3.6.6. This affects an unknown part of the component DICOM File Handler. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2022-2121. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-43272 | DCMTK 3.6.7 T_ASC_Association memory leak (Nessus ID 214857)
10 months 2 weeks ago
A vulnerability was found in DCMTK 3.6.7. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument T_ASC_Association leads to memory leak.
This vulnerability is handled as CVE-2022-43272. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
Israeli Firm Paragon Attack WhatsApp With New Zero-Click Spyware
10 months 2 weeks ago
WhatsApp revealed on Friday that a “zero-click” spyware attack, attributed to the Israeli firm Paragon, has targeted scores of users worldwide, including journalists and members of civil society. The spyware targeted nearly 100 WhatsApp users, including journalists, and did not require any user interaction, nor did it require clicking links or opening attachments, making it […]
The post Israeli Firm Paragon Attack WhatsApp With New Zero-Click Spyware appeared first on Cyber Security News.
Balaji N
Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists
10 months 2 weeks ago
Meta-owned WhatsApp on Friday said it disrupted a campaign that involved the use of spyware to target journalists and civil society members.
The campaign, which targeted around 90 members, involved the use of spyware from an Israeli company known as Paragon Solutions. The attackers were neutralized in December 2024.
In a statement to The Guardian, the encrypted messaging app said it has reached
The Hacker News
CVE-2024-57775 | JFinalOA 1.0.2 getWorkFlowHis?insid sql injection
10 months 2 weeks ago
A vulnerability was found in JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file getWorkFlowHis?insid. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2024-57775. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-9406 | Google Android NlpService permission
10 months 2 weeks ago
A vulnerability was found in Google Android. It has been declared as critical. This vulnerability affects unknown code of the component NlpService. The manipulation leads to permission issues.
This vulnerability was named CVE-2018-9406. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-12104 | Visual Website Collaboration, Feedback & Project Management Plugin Project Page authorization
10 months 2 weeks ago
A vulnerability was found in Visual Website Collaboration, Feedback & Project Management Plugin up to 4.0.9 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Project Page. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-12104. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-0371 | Jet Elements Plugin up to 2.7.2.1 on WordPress Widget cross site scripting
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Jet Elements Plugin up to 2.7.2.1 on WordPress. This affects an unknown part of the component Widget. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-0371. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com