Aggregator
.NET 安全攻防知识交流社区
11 months ago
.NET内网实战:通过FSharp白名单执行命令
11 months ago
DockerSpy - DockerSpy Searches For Images On Docker Hub And Extracts Sensitive Information Such As Authentication Secrets, Private Keys, And More
11 months ago
DockerSpy searches for images on Docker Hub and extracts sensitive information such as authent
CVE-2007-2601 | Divx City GDivX Zenith Player 1.0.0.1 ActiveX Control fix.dll memory corruption (EDB-3889 / XFDB-34246)
11 months ago
A vulnerability classified as very critical has been found in Divx City GDivX Zenith Player 1.0.0.1. Affected is an unknown function in the library fix.dll of the component ActiveX Control. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2007-2601. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-2600 | Wavelink Media TutorialCMS 1.00 browsecat.php search cross site scripting (EDB-3887 / XFDB-34215)
11 months ago
A vulnerability was found in Wavelink Media TutorialCMS 1.00. It has been rated as critical. This issue affects some unknown processing of the file browsecat.php. The manipulation of the argument search leads to basic cross site scripting.
The identification of this vulnerability is CVE-2007-2600. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-6744 | Al-Ahsa News 2 X.509 Certificate cryptographic issues (VU#582497)
11 months ago
A vulnerability, which was classified as critical, was found in Al-Ahsa News 2. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-6744. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2021-30807 | Apple watchOS IOMobileFrameBuffer memory corruption
11 months ago
A vulnerability, which was classified as critical, has been found in Apple watchOS. Affected by this issue is some unknown functionality of the component IOMobileFrameBuffer. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2021-30807. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-30807 | Apple macOS IOMobileFrameBuffer memory corruption
11 months ago
A vulnerability, which was classified as critical, was found in Apple macOS. This affects an unknown part of the component IOMobileFrameBuffer. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2021-30807. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-30860 | Apple iOS/iPadOS up to 14.7.1 CoreGraphics FORCEDENTRY integer overflow (HT212807)
11 months ago
A vulnerability classified as critical was found in Apple iOS and iPadOS up to 14.7.1. This vulnerability affects unknown code of the component CoreGraphics. The manipulation leads to integer overflow.
This vulnerability was named CVE-2021-30860. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-30860 | Apple watchOS up to 7.6.1 CoreGraphics integer overflow (HT212806)
11 months ago
A vulnerability classified as critical was found in Apple watchOS up to 7.6.1. Affected by this vulnerability is an unknown functionality of the component CoreGraphics. The manipulation leads to integer overflow.
This vulnerability is known as CVE-2021-30860. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-30860 | Apple macOS up to 11.5.2 CoreGraphics integer overflow (HT212804)
11 months ago
A vulnerability, which was classified as critical, has been found in Apple macOS up to 11.5.2. Affected by this issue is some unknown functionality of the component CoreGraphics. The manipulation leads to integer overflow.
This vulnerability is handled as CVE-2021-30860. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-6743 | Lipbrau Hearsay: A Social Party Game 1.7.000 X.509 Certificate cryptographic issues (VU#582497)
11 months ago
A vulnerability, which was classified as critical, has been found in Lipbrau Hearsay: A Social Party Game 1.7.000. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-6743. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2013-1414 | Fortinet FortiOS 4.3.10/4.3.12/5.0/5.0.1 System functions shutdown URL cross-site request forgery (EDB-26528 / Nessus ID 73527)
11 months ago
A vulnerability, which was classified as problematic, was found in Fortinet FortiOS 4.3.10/4.3.12/5.0/5.0.1. This affects an unknown part of the file system/maintenance/shutdown of the component System functions. The manipulation as part of URL leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2013-1414. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-0135 | Microsoft Edge Security Feature access control (MS17-007 / Nessus ID 97730)
11 months ago
A vulnerability was found in Microsoft Edge. It has been classified as critical. Affected is an unknown function of the component Security Feature. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2017-0135. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2007-2599 | TutorialCMS search.php search sql injection (EDB-3887 / XFDB-34214)
11 months ago
A vulnerability has been found in TutorialCMS and classified as critical. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument search leads to sql injection.
This vulnerability is known as CVE-2007-2599. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-6742 | All around Cyprus 2.11 X.509 Certificate cryptographic issues (VU#582497)
11 months ago
A vulnerability classified as critical was found in All around Cyprus 2.11. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-6742. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2009-5114 | Iwork WebGlimpse up to 2.2.2 WebGL wgarcmin.cgi DOC path traversal (EDB-36994 / XFDB-74321)
11 months ago
A vulnerability was found in Iwork WebGlimpse up to 2.2.2. It has been classified as problematic. Affected is an unknown function of the file wgarcmin.cgi of the component WebGL. The manipulation of the argument DOC leads to path traversal.
This vulnerability is traded as CVE-2009-5114. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-6741 | Tribunenews365 John MacArthur 1.0.26 X.509 Certificate cryptographic issues (VU#582497)
11 months ago
A vulnerability classified as critical has been found in Tribunenews365 John MacArthur 1.0.26. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-6741. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2007-1566 | NetVIOS NewsID sql injection (EDB-3520 / XFDB-33072)
11 months ago
A vulnerability has been found in NetVIOS and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument NewsID leads to sql injection.
This vulnerability is known as CVE-2007-1566. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com