Aggregator
云存储桶可以实现列对象的一种绕过思路
3 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
ISC Stormcast For Friday, May 1st, 2026 https://isc.sans.edu/podcastdetail/9914, (Fri, May 1st)
3 months ago
五一劳动节快乐!
3 months ago
CVE-2026-42512 | FreeBSD dhclient heap-based overflow (WID-SEC-2026-1324)
3 months ago
A vulnerability labeled as critical has been found in FreeBSD. This affects an unknown function of the component dhclient. The manipulation results in heap-based buffer overflow.
This vulnerability was named CVE-2026-42512. The attack may be performed from remote. There is no available exploit.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2026-42511 | FreeBSD up to p2/p6/p11/p12 BOOTP File dhclient.conf quoting syntax (WID-SEC-2026-1324)
3 months ago
A vulnerability classified as critical was found in FreeBSD up to p2/p6/p11/p12. This impacts an unknown function of the file dhclient.conf of the component BOOTP File Handler. Such manipulation leads to improper neutralization of quoting syntax.
This vulnerability is listed as CVE-2026-42511. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-39457 | FreeBSD File Descriptor stack-based overflow (WID-SEC-2026-1324)
3 months ago
A vulnerability classified as critical has been found in FreeBSD. Affected by this vulnerability is an unknown functionality of the component File Descriptor Handler. Performing a manipulation results in stack-based buffer overflow.
This vulnerability is identified as CVE-2026-39457. The attack is only possible with local access. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-35547 | FreeBSD Message heap-based overflow (WID-SEC-2026-1324)
3 months ago
A vulnerability classified as critical has been found in FreeBSD. The affected element is an unknown function of the component Message Handler. This manipulation causes heap-based buffer overflow.
The identification of this vulnerability is CVE-2026-35547. The attack needs to be done within the local network. There is no exploit available.
It is suggested to install a patch to address this issue.
vuldb.com
Aur0ra
3 months ago
You must login to view this content
cohenido
Aur0ra
3 months ago
You must login to view this content
cohenido
CVE-2026-6868 | Wireshark up to 4.4.14/4.6.4 HTTP Protocol Dissector stack-based overflow (EUVD-2026-26309 / WID-SEC-2026-1311)
3 months ago
A vulnerability was found in Wireshark up to 4.4.14/4.6.4. It has been rated as critical. This affects an unknown part of the component HTTP Protocol Dissector. This manipulation causes stack-based buffer overflow.
This vulnerability is handled as CVE-2026-6868. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-6869 | Wireshark up to 4.4.14/4.6.4 WebSocket Protocol Dissector improperly controlled sequential memory allocation (WID-SEC-2026-1311)
3 months ago
A vulnerability marked as problematic has been reported in Wireshark up to 4.4.14/4.6.4. This issue affects some unknown processing of the component WebSocket Protocol Dissector. The manipulation leads to improperly controlled sequential memory allocation.
This vulnerability is uniquely identified as CVE-2026-6869. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-6537 | Wireshark up to 4.4.14/4.6.4 ZigBee Protocol Dissector stack-based overflow (ID 21125 / WID-SEC-2026-1311)
3 months ago
A vulnerability was found in Wireshark up to 4.4.14/4.6.4. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component ZigBee Protocol Dissector. This manipulation causes stack-based buffer overflow.
This vulnerability appears as CVE-2026-6537. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-6538 | Wireshark up to 4.4.14/4.6.4 BEEP Protocol Dissector stack-based overflow (ID 21120 / WID-SEC-2026-1311)
3 months ago
A vulnerability identified as critical has been detected in Wireshark up to 4.4.14/4.6.4. This affects an unknown part of the component BEEP Protocol Dissector. Performing a manipulation results in stack-based buffer overflow.
This vulnerability is known as CVE-2026-6538. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-6535 | Wireshark up to 4.4.14/4.6.4 zlib Decompression improperly controlled sequential memory allocation (ID 21097 / WID-SEC-2026-1311)
3 months ago
A vulnerability was found in Wireshark up to 4.4.14/4.6.4. It has been classified as problematic. This impacts an unknown function of the component zlib Decompression Handler. The manipulation leads to improperly controlled sequential memory allocation.
This vulnerability is documented as CVE-2026-6535. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-6536 | Wireshark up to 4.6.4 DLMS COSEM Protocol infinite loop (ID 21065 / WID-SEC-2026-1311)
3 months ago
A vulnerability was found in Wireshark up to 4.6.4. It has been declared as problematic. Affected is an unknown function of the component DLMS COSEM Protocol. The manipulation results in infinite loop.
This vulnerability is reported as CVE-2026-6536. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-6534 | Wireshark up to 4.4.14/4.6.4 USB HID Protocol Dissector infinite loop (ID 21121 / WID-SEC-2026-1311)
3 months ago
A vulnerability was found in Wireshark up to 4.4.14/4.6.4 and classified as problematic. This affects an unknown function of the component USB HID Protocol Dissector. Executing a manipulation can lead to infinite loop.
This vulnerability is registered as CVE-2026-6534. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
Need help
3 months ago
诚邀渠道合作伙伴共启新征程
3 months ago
【火绒安全周报】部分AI工具平台被查/伊朗黑客公布美军信息
3 months ago
【火绒安全周报】Vercel遭黑客入侵/黑客多次入侵美最高法院