Aggregator
河南一高校泄露个人信息被通报,内部紧急通知整改
3 days 7 hours ago
该校被上级公安部门及教育主管部门通报
【高级威胁追踪(APT)】amdc6766团伙最新双平台特马攻击事件分析
3 days 7 hours ago
2025年8月,深信服深瞻情报实验室再次监测到amdc6766黑产组织攻击活动。在本次攻击活动中,观察到多个运维管理工具相关样本,疑似利用仿冒网站分发恶意文件。
CVE-2025-41242 | VMware Spring Framework up to 5.3.43/6.0.29/6.1.21/6.2.9 Servlet Container path traversal
3 days 7 hours ago
A vulnerability classified as problematic has been found in VMware Spring Framework up to 5.3.43/6.0.29/6.1.21/6.2.9. This issue affects some unknown processing of the component Servlet Container Handler. Performing manipulation results in path traversal.
This vulnerability is known as CVE-2025-41242. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49752 | Linux Kernel up to 5.15.90/6.1.8 fwnode_graph_get_next_endpoint parent reference count (Nessus ID 246852 / WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.15.90/6.1.8. Impacted is the function fwnode_graph_get_next_endpoint. The manipulation of the argument parent leads to improper update of reference count.
This vulnerability is uniquely identified as CVE-2022-49752. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2022-49751 | Linux Kernel up to 6.1.8 w1_process state issue (Nessus ID 240793 / WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.1.8. Affected is the function w1_process. The manipulation leads to state issue.
This vulnerability is documented as CVE-2022-49751. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2022-49753 | Linux Kernel up to 6.1.8 dmaengine lib/refcount.c dma_chan_get use after free (Nessus ID 234965 / WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability was found in Linux Kernel up to 6.1.8. It has been declared as critical. Affected by this issue is the function dma_chan_get in the library lib/refcount.c of the component dmaengine. Executing manipulation can lead to use after free.
This vulnerability is registered as CVE-2022-49753. The attack requires access to the local network. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49748 | Linux Kernel up to 5.4.230/5.10.165/5.15.90/6.1.8 amd integer overflow (Nessus ID 241018 / WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability was found in Linux Kernel up to 5.4.230/5.10.165/5.15.90/6.1.8 and classified as problematic. Impacted is an unknown function of the component amd. The manipulation results in integer overflow.
This vulnerability is identified as CVE-2022-49748. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2022-49750 | Linux Kernel up to 6.1.8 cpufreq _CPC buffer overflow (WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability was found in Linux Kernel up to 6.1.8. It has been rated as critical. This affects an unknown function of the component cpufreq. Performing manipulation of the argument _CPC results in buffer overflow.
This vulnerability is cataloged as CVE-2022-49750. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2022-49749 | Linux Kernel up to 5.10.165/5.15.90/6.1.8 i2c_dw_scl_lcnt privilege escalation (Nessus ID 237099 / WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability has been found in Linux Kernel up to 5.10.165/5.15.90/6.1.8 and classified as problematic. This issue affects the function i2c_dw_scl_lcnt. The manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2022-49749. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2022-49747 | Linux Kernel up to 5.15.91/6.1.9 erofs/zmap.c iomap_iter_done denial of service (WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability was found in Linux Kernel up to 5.15.91/6.1.9. It has been declared as critical. The impacted element is the function iomap_iter_done of the file erofs/zmap.c. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2022-49747. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
国内几个大厂测试的几个感受
3 days 7 hours ago
Gemini теперь сам встраивает бэкдоры в код — достаточно сказать «Добавь комментарий»
3 days 7 hours ago
Когда UI пуст, а ИИ слышит команды.
Man Jailed for 20 Months After Compromising Millions of Accounts
3 days 7 hours ago
Al-Tahery Al-Mashriky has been sentenced to 20 months behind bars for hacktism-related offenses
CVE-2022-49745 | Linux Kernel up to 6.1.10 m10bmc-sec privilege escalation (WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability was found in Linux Kernel up to 6.1.10 and classified as problematic. The impacted element is an unknown function of the component m10bmc-sec. The manipulation results in privilege escalation.
This vulnerability is cataloged as CVE-2022-49745. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2022-49746 | Linux Kernel up to 4.19.271/5.4.230/5.10.166/5.15.91/6.1.9 imx-sdma sdma_load_context memory leak (WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability was found in Linux Kernel up to 4.19.271/5.4.230/5.10.166/5.15.91/6.1.9. It has been classified as critical. This affects the function sdma_load_context of the component imx-sdma. This manipulation causes memory leak.
This vulnerability is registered as CVE-2022-49746. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-49744 | Linux Kernel up to 6.1.10 uffd fork information disclosure (Nessus ID 247369 / WID-SEC-2025-0649)
3 days 7 hours ago
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.1.10. Affected by this vulnerability is the function fork of the component uffd. Executing manipulation can lead to information disclosure.
This vulnerability appears as CVE-2022-49744. The attack may be performed from a remote location. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-5048 | Autodesk AutoCAD prior 2026.1 DGN File Parser buffer overflow (EUVD-2025-25033 / WID-SEC-2025-1853)
3 days 7 hours ago
A vulnerability was found in Autodesk AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, AutoCAD MAP 3D, Civil 3D and Advance Steel and classified as critical. This impacts an unknown function of the component DGN File Parser. Executing manipulation can lead to buffer overflow.
This vulnerability is handled as CVE-2025-5048. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-5047 | Autodesk AutoCAD prior 2026.1 DGN File Parser Uninitialized uninitialized variable (EUVD-2025-25034 / WID-SEC-2025-1853)
3 days 7 hours ago
A vulnerability has been found in Autodesk AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, AutoCAD MAP 3D, Civil 3D and Advance Steel and classified as critical. This affects an unknown function of the component DGN File Parser. Performing manipulation of the argument Uninitialized results in use of uninitialized variable.
This vulnerability is known as CVE-2025-5047. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2025-5046 | Autodesk AutoCAD prior 2026.1 DGN File Parser out-of-bounds (EUVD-2025-25035 / WID-SEC-2025-1853)
3 days 7 hours ago
A vulnerability, which was classified as problematic, was found in Autodesk AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, AutoCAD MAP 3D, Civil 3D and Advance Steel. The impacted element is an unknown function of the component DGN File Parser. Such manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2025-5046. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com