Aggregator
HeArBERT: A Bilingual Model for Arabic-Hebrew Translation Using Transliteration
1 year 9 months ago
Authors:(1) Aviad Rom, The Data Science Institute, Reichman University, Herzliya, Israel;(2) Kfir
CVE-2007-2545 | Persism CMS latest_posts.php system[path] memory corruption (EDB-3853 / XFDB-34102)
1 year 9 months ago
A vulnerability was found in Persism CMS. It has been classified as critical. Affected is an unknown function of the file modules/forums/blocks/latest_posts.php. The manipulation of the argument system[path] leads to memory corruption.
This vulnerability is traded as CVE-2007-2545. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
利用CloudFlare Pages和R2实现的免费图床
1 year 9 months ago
一款基于Cloudflare的Worker、R2、Pages实现的图床应用,具有以下特点:
10GB的免费存储空间
每月300W次的不计流量的图片访问,每天10W的限制。
每月100W次的图...
黑海洋
CVE-2024-41066 | Linux Kernel up to 6.1.100/6.6.41/6.9.10 ibmvnic memory leak
1 year 9 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.100/6.6.41/6.9.10. Affected is an unknown function of the component ibmvnic. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2024-41066. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38886 | Horizon Business Services Caterease up to 24.0.1.2405 TCP Traffic verification of source
1 year 9 months ago
A vulnerability has been found in Horizon Business Services Caterease up to 24.0.1.2405 and classified as critical. This vulnerability affects unknown code of the component TCP Traffic Handler. The manipulation leads to improper verification of source of a communication channel.
This vulnerability was named CVE-2024-38886. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-38889 | Horizon Business Services Caterease up to 24.0.1.2405 TCP Packet sql injection
1 year 9 months ago
A vulnerability was found in Horizon Business Services Caterease up to 24.0.1.2405. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TCP Packet Handler. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-38889. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-42349 | FOGproject FOG up to 1.5.10.41.4 fog_login_accepted.log log file (GHSA-697m-3c4p-g29h)
1 year 9 months ago
A vulnerability was found in FOGproject FOG up to 1.5.10.41.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file fog_login_accepted.log. The manipulation leads to sensitive information in log files.
This vulnerability is handled as CVE-2024-42349. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42348 | FOGproject FOG up to 1.5.10.41.2 Computer Registration command injection (GHSA-456c-4gw3-c9xw)
1 year 9 months ago
A vulnerability classified as critical was found in FOGproject FOG up to 1.5.10.41.2. This vulnerability affects unknown code of the component Computer Registration Handler. The manipulation leads to command injection.
This vulnerability was named CVE-2024-42348. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42287 | Linux Kernel up to 6.1.102/6.6.43/6.10.2 qla2xxx null pointer dereference
1 year 9 months ago
A vulnerability has been found in Linux Kernel up to 6.1.102/6.6.43/6.10.2 and classified as critical. This vulnerability affects unknown code of the component qla2xxx. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-42287. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42298 | Linux Kernel up to 6.6.43/6.10.2 ASoC devm_kasprintf null pointer dereference (b4205dfcfe96/af466037fa2b/e62599902327)
1 year 9 months ago
A vulnerability classified as critical was found in Linux Kernel up to 6.6.43/6.10.2. This vulnerability affects the function devm_kasprintf of the component ASoC. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-42298. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42286 | Linux Kernel up to 6.1.102/6.6.43/6.10.2 qla_nvme_register_remote null pointer dereference
1 year 9 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.102/6.6.43/6.10.2. Affected is the function qla_nvme_register_remote. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-42286. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Chinese ‘Crimson Palace’ espionage campaign keeps hacking Southeast Asian governments
1 year 9 months ago
A high-stakes cat and mouse game between defenders and a sophisticated trio of Chinese cyberespiona
Training a Bilingual Language Model by Mapping Tokens onto a Shared Character Space
1 year 9 months ago
Authors:(1) Aviad Rom, The Data Science Institute, Reichman University, Herzliya, Israel;(2) Kfir
79 уязвимостей и 4 0Day: как прошел Patch Tuesday у Microsoft
1 year 9 months ago
В сентябрьский вторник исправлений компания избавила пользователей от критических ошибок.
CVE-2017-8718 | Microsoft Windows up to Server 2016 JET Database Engine memory corruption (KB4041676 / Nessus ID 103745)
1 year 9 months ago
A vulnerability classified as critical has been found in Microsoft Windows. This affects an unknown part of the component JET Database Engine. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2017-8718. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
索尼宣布售价 700 美元的 PS5 Pro
1 year 9 months ago
索尼宣布了售价高达 700 美元的 PS5 Pro,没有光驱的数字下载版本。如果想要光驱和直立架则需要额外付费。PS5 Pro 将于 11 月 7 日发售。PS5 Pro 和 PS5 一样,搭配 AMD SoC,其中 CPU 部分没有改变,但 GPU 部分的计算单元(CU)增加了 67%——PS5 有 36 CU,意味着 PS5 Pro 有 60 CU。此外内存速度提升 28% 至 18 Gbps。PS5 Pro 渲染性能提升了 45%,还显著改进了光线追踪性能,引入了 AI 驱动的上采样技术 PlayStation Spectral Super Resolution(PSSR)。PSSR 利用了 AMD XDNA 2 架构的 NPU。
Cybersecurity is a fundamental component of patient care and safety
1 year 9 months ago
Healthcare institutions are custodians of vast repositories of sensitive patient data, encompassing comprehensive health histories, insurance profiles, and billing data. The ramifications of a data breach often extend far beyond the immediate task of patching the vulnerabilities and notifying the affected parties. Often, the less visible costs of these incidents can be equally, if not more, devastating to healthcare providers and the patients they serve. The aftermath of a cyberattack can reverberate for months, impacting … More →
The post Cybersecurity is a fundamental component of patient care and safety appeared first on Help Net Security.
Help Net Security
Microsoft fixes Windows Server performance issues from August updates
1 year 9 months ago
error code: 1106
ZDI-CAN-25191: Hugging Face
1 year 9 months ago
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'The_Kernel_Panic' was reported to the affected vendor on: 2024-09-11, 63 days ago. The vendor is given until 2025-01-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.