Aggregator
你站在哪里
1 month 2 weeks ago
上一篇顺口溜中的方法论我们讲了成长的内在五步:读书、行路、阅人、问师、领悟。但有一个问题没有回答:这五步,你在哪里迈?
CVE-2014-2182 | Cisco ASA DHCPv6 input validation (CSCun45520 / Nessus ID 74036)
1 month 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Cisco ASA. This issue affects some unknown processing of the component DHCPv6. This manipulation causes improper input validation.
This vulnerability is registered as CVE-2014-2182. The attack requires access to the local network. No exploit is available.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2014-2183 | Cisco IOS XE up to 3.10S(.2) ESP Card L2TP Packet input validation (CSCun09973 / XFDB-92862)
1 month 2 weeks ago
A vulnerability was found in Cisco IOS XE up to 3.10S(.2) and classified as problematic. The impacted element is an unknown function of the component ESP Card L2TP Packet Handler. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2014-2183. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2014-2180 | Cisco Unified Contact Center input validation (CSCun74133 / XFDB-92867)
1 month 2 weeks ago
A vulnerability marked as problematic has been reported in Cisco Unified Contact Center. The affected element is an unknown function. This manipulation causes improper input validation.
The identification of this vulnerability is CVE-2014-2180. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2014-2184 | Cisco Unified Communications Manager IP Manager Assistant input validation (CSCun74352 / XFDB-92863)
1 month 2 weeks ago
A vulnerability described as problematic has been identified in Cisco Unified Communications Manager. The impacted element is an unknown function of the component IP Manager Assistant. Such manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2014-2184. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2014-2185 | Cisco Unified Communications Manager Call Detail Records information disclosure (CSCun74374 / XFDB-92865)
1 month 2 weeks ago
A vulnerability classified as problematic has been found in Cisco Unified Communications Manager. This affects an unknown function of the component Call Detail Records Handler. Performing a manipulation results in information disclosure.
This vulnerability is identified as CVE-2014-2185. The attack can be initiated remotely. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2014-1841 | South River Technologies Titan FTP Server up to 10.0.1732 src path traversal (EDB-31579 / ID 121809)
1 month 2 weeks ago
A vulnerability was found in South River Technologies Titan FTP Server up to 10.0.1732. It has been classified as problematic. The affected element is an unknown function. The manipulation of the argument src leads to path traversal.
This vulnerability is referenced as CVE-2014-1841. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2014-1842 | South River Technologies Titan FTP Server up to 10.0.1732 path traversal (EDB-31579 / ID 121809)
1 month 2 weeks ago
A vulnerability was found in South River Technologies Titan FTP Server up to 10.0.1732. It has been declared as problematic. The impacted element is an unknown function. The manipulation results in path traversal.
This vulnerability is identified as CVE-2014-1842. The attack can be executed remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-1843 | South River Technologies Titan FTP Server up to 10.0.1732 src path traversal (EDB-31579 / ID 121809)
1 month 2 weeks ago
A vulnerability was found in South River Technologies Titan FTP Server up to 10.0.1732. It has been rated as problematic. This affects an unknown function. This manipulation of the argument src causes path traversal.
This vulnerability is tracked as CVE-2014-1843. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
vuldb.com
CVE-2013-7063 | Invitation 7.x-2.0/7.x-2.1 access control
1 month 2 weeks ago
A vulnerability categorized as problematic has been discovered in Invitation 7.x-2.0/7.x-2.1. This impacts an unknown function. Such manipulation leads to improper access controls.
This vulnerability is listed as CVE-2013-7063. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2013-7064 | Freelance-it-consultant EU Cookie Compliance up to 7.x-1.8 cross site scripting
1 month 2 weeks ago
A vulnerability identified as problematic has been detected in Freelance-it-consultant EU Cookie Compliance up to 7.x-1.8. Affected is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2013-7064. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2013-7065 | Organic Groups 5/6.x-1.0-rc8/6.x-2.1/7.x-1.1 Access Restriction access control
1 month 2 weeks ago
A vulnerability labeled as critical has been found in Organic Groups 5/6.x-1.0-rc8/6.x-2.1/7.x-1.1. Affected by this vulnerability is an unknown functionality of the component Access Restriction. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2013-7065. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
npm 曝大规模供应链攻击:TanStack 生态被投毒,可窃取云密钥与GitHub令牌
1 month 2 weeks ago
流行的前端开发库 TanStack 生态(包括 Router, History 等)确认遭遇严重的供应链攻击。攻击者利用受损的 GitHub Actions 工作流,
斯柯达数据泄露事件波及在线商店客户
1 month 2 weeks ago
汽车制造商斯柯达(Skoda)披露了一起数据泄露事件,涉及其在线商店用户的个人信息。 该公司表示,此次事件是在其技术安全监测过程中发现的,是门户网站软件存在漏洞导致的。 得知此次网络攻击后,这家汽车制造商立即关闭了在线商店,修补了被利用的漏洞,重新评估了现有安全机制,并聘请了外部取证专家协助调查,同时通知了相关当局。 斯柯达解释称,黑客利用该漏洞访问了商店...
hackernews
斯柯达数据泄露事件波及在线商店客户
1 month 2 weeks ago
error code: 1003
苹果发布iOS 26.5正式版 主要修复各类安全漏洞和已知错误
1 month 2 weeks ago
2026年5月12日 10:52iOS, 系统资讯01.65K
CVE-2026-8344 | D-Link DIR-816 1.10CNB05_R1B011D88210 /goform/formDMZ.cgi sub_445E7C command injection (EUVD-2026-29345)
1 month 2 weeks ago
A vulnerability has been found in D-Link DIR-816 1.10CNB05_R1B011D88210 and classified as critical. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection.
The identification of this vulnerability is CVE-2026-8344. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2026-34963 | Barebox up to 2026.04.0 EFI PE Loader efi/loader/pe.c VirtualAddress/size integer overflow (EUVD-2026-29347)
1 month 2 weeks ago
A vulnerability labeled as problematic has been found in Barebox up to 2026.04.0. Affected by this issue is some unknown functionality of the file efi/loader/pe.c of the component EFI PE Loader. Such manipulation of the argument VirtualAddress/size leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-34963. Local access is required to approach this attack. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-8346 | D-Link DIR-816 1.10CNB05_R1B011D88210 portForward ip_address command injection (EUVD-2026-29349)
1 month 2 weeks ago
A vulnerability was found in D-Link DIR-816 1.10CNB05_R1B011D88210. It has been classified as critical. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection.
This vulnerability is identified as CVE-2026-8346. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com