Aggregator
CVE-2020-35665 | TerraMaster TOS up to 4.2.06 CSV include/makecvs.php Event os command injection (EDB-49330)
10 months ago
A vulnerability was found in TerraMaster TOS up to 4.2.06. It has been classified as very critical. Affected is an unknown function of the file include/makecvs.php of the component CSV Handler. The manipulation of the argument Event leads to os command injection.
This vulnerability is traded as CVE-2020-35665. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
开源虚拟化软件QEMU 9.1正式版发布 改进Arm和RISC-V平台的硬件支持
10 months ago
美国大学学生成绩膨胀
10 months ago
当绝大部分学生都是 A 时,成绩的激励价值就失去了意义。美国大学的分数膨胀已经失控。统计数据显示,1950 年哈佛大学平均 GPA 为 2.6/4分,2003 年提高到 3.4 分。大学越精英,评分标准就越宽大。耶鲁大学在 2023 年有五分之四的学生获得了 A 或 A-。普通大学的情况类似。今天美国所有四年制大学最常见的成绩是 A。A 如今已经不再是特别学术成就的标志了。Richard Arum 和 Josipa Roksa 在其 2011 年出版的作品《Academically Adrift》中指出,1960 年后的 50 年里,全日制大学生平均学习时间少了一半,降至每周十二个小时。大部分大学生在批判性思维、复杂推理和写作测试中没有取得显著进步,半数学生在接受高等教育的前两年没有取得任何进步。
CVE-2014-5936 | INCOgnito Private Browser 1.4.0 X.509 Certificate cryptographic issues (VU#582497)
10 months ago
A vulnerability was found in INCOgnito Private Browser 1.4.0. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-5936. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2014-5935 | Daily Free App @ Amazon 1.5.2 X.509 Certificate cryptographic issues (VU#582497)
10 months ago
A vulnerability was found in Daily Free App @ Amazon 1.5.2. It has been declared as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-5935. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
中英状态实时显示 – 光标处实时显示输入法中英状态[Windows]
10 months ago
波音星际航线CST-100脱离国际空间站正在无人驾驶返回地球途中
10 months ago
CVE-2007-2187 | eXtremail 2.1/2.1.1 stack-based overflow (EDB-3769 / BID-23577)
10 months ago
A vulnerability, which was classified as very critical, was found in eXtremail 2.1/2.1.1. This affects an unknown part. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2007-2187. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Telegram轻博客和图床平台Telegraph将限制发布新图片 主要存在违规内容
10 months ago
CVE-2017-13006 | Apple macOS up to 10.13.1 tcpdump memory corruption (HT208221 / Nessus ID 100472)
10 months ago
A vulnerability classified as very critical has been found in Apple macOS up to 10.13.1. This affects an unknown part of the component tcpdump. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2017-13006. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
加入 AI 混战,蚂蚁全面加速「卷应用」
10 months ago
发布三个 AI 管家的蚂蚁,要从生活场景全面切入 AI 应用。
微软发布Windows Server 2025新预览版调整时间炸弹 请用户尽快更新
10 months ago
A flaw in WordPress LiteSpeed Cache Plugin allows account takeover
10 months ago
A critical flaw in the LiteSpeed Cache plugin for WordPress could allow unauthenticated users to take control of arbitrary accounts. The LiteSpeed Cache plugin is a popular caching plugin for WordPress that accounts for over 5 million active installations. The plugin offers site acceleration through server-level caching and various optimization features. The LiteSpeed Cache plugin […]
Pierluigi Paganini
CVE-2007-2180 | NullSoft WinAmp 5.3 memory corruption (EDB-3768 / XFDB-33764)
10 months ago
A vulnerability was found in NullSoft WinAmp 5.3 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2007-2180. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
《黑神话:悟空》欢乐圆桌:聊聊游戏内外的趣事儿
10 months ago
《黑神话:悟空》欢乐圆桌:聊聊游戏内外的趣事儿 少数派播客 等 4 位作者 11:00 《黑神话:悟空》是近期突破了各个次元壁的现象级话题,也是每个游戏玩家都不得不聊的佳作。在本期节目中,《少数派播
微软将在Microsoft Office 2024中默认关闭ActiveX控件提高整体安全性
10 months ago
CVE-2024-34158 | Google Go up to 1.22.6/1.23.0 go-build-constraint resource consumption
10 months ago
A vulnerability classified as problematic has been found in Google Go up to 1.22.6/1.23.0. Affected is an unknown function of the component go-build-constraint. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-34158. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45034 | Apache Airflow up to 2.10.0 DAG Folder unnecessary privileges
10 months ago
A vulnerability was found in Apache Airflow up to 2.10.0 and classified as critical. Affected by this issue is some unknown functionality of the component DAG Folder Handler. The manipulation leads to execution with unnecessary privileges.
This vulnerability is handled as CVE-2024-45034. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7652 | Mozilla Thunderbird ECMA-262 type confusion
10 months ago
A vulnerability was found in Mozilla Thunderbird. It has been declared as critical. This vulnerability affects unknown code of the component ECMA-262 Handler. The manipulation leads to type confusion.
This vulnerability was named CVE-2024-7652. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com