Aggregator
向每一位劳动者致敬!
3 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
威努特五一假期业务保障通知
3 months ago
假期值守,保障业务无忧。
威努特五一假期业务保障通知
3 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
Discovering Vulnerabilities in Enterprise Audiovisual Hardware
3 months ago
May 1, 2026 · 2647 words
CVE-2026-39984 | sigstore timestamp-authority up to 2.0.5 certificate validation (EUVD-2026-22813 / Nessus ID 311219)
3 months ago
A vulnerability, which was classified as critical, has been found in sigstore timestamp-authority up to 2.0.5. This issue affects some unknown processing. This manipulation causes improper certificate validation.
This vulnerability is registered as CVE-2026-39984. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-40312 | ImageMagick up to 7.1.2-18 MSL Decoder off-by-one (GHSA-5xg3-585r-9jh5 / Nessus ID 311220)
3 months ago
A vulnerability, which was classified as problematic, was found in ImageMagick up to 7.1.2-18. The impacted element is an unknown function of the component MSL Decoder. Such manipulation leads to off-by-one.
This vulnerability is traded as CVE-2026-40312. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-40311 | ImageMagick up to 6.9.13-43/7.1.2-18 XMP Profile use after free (GHSA-r83h-crwp-3vm7 / Nessus ID 311220)
3 months ago
A vulnerability, which was classified as critical, has been found in ImageMagick up to 6.9.13-43/7.1.2-18. The affected element is an unknown function of the component XMP Profile Handler. This manipulation causes use after free.
This vulnerability appears as CVE-2026-40311. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
Former incident responders sentenced to 4 years in prison for committing ransomware attacks
3 months ago
Ryan Goldberg and Kevin Martin attacked five companies in 2023 and extorted nearly $1.3 million from one of their victims.
The post Former incident responders sentenced to 4 years in prison for committing ransomware attacks appeared first on CyberScoop.
Matt Kapko
CVE-2010-0106 | Symantec Client Security up to 3.0 denial of service (Nessus ID 69956 / ID 116927)
3 months ago
A vulnerability classified as problematic was found in Symantec Client Security up to 3.0. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2010-0106. The attack requires local access. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2010-0663 | Google Chrome up to 2.0.172.32 Read information disclosure (Nessus ID 44317 / ID 116835)
3 months ago
A vulnerability was found in Google Chrome up to 2.0.172.32. It has been classified as problematic. This affects the function ParamTraits<SkBitmap>::Read. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2010-0663. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2010-0664 | Google Chrome up to 2.0.172.32 view-source CanRequestURL resource management (Nessus ID 44317 / ID 116835)
3 months ago
A vulnerability was found in Google Chrome up to 2.0.172.32. It has been declared as problematic. This vulnerability affects the function ChildProcessSecurityPolicy::CanRequestURL of the component view-source. Such manipulation leads to improper resource management.
This vulnerability is referenced as CVE-2010-0664. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-0416 | RealNetworks RealPlayer 1.0.6 Unescape memory corruption (EDB-33620 / Nessus ID 44428)
3 months ago
A vulnerability was found in RealNetworks RealPlayer 1.0.6. It has been rated as critical. This issue affects the function Unescape. Performing a manipulation results in memory corruption.
This vulnerability is identified as CVE-2010-0416. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2010-0417 | RealNetworks Helix Player 1.0.6 memory corruption (Nessus ID 44428 / ID 155701)
3 months ago
A vulnerability categorized as critical has been discovered in RealNetworks Helix Player 1.0.6. Impacted is an unknown function. Executing a manipulation can lead to memory corruption.
This vulnerability is tracked as CVE-2010-0417. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2009-4644 | Accellion Secure File Transfer Appliance 7 0 135 Ping Command os command injection (XFDB-56248 / BID-38176)
3 months ago
A vulnerability identified as critical has been detected in Accellion Secure File Transfer Appliance 7 0 135. The affected element is an unknown function of the component Ping Command. The manipulation leads to os command injection.
This vulnerability is listed as CVE-2009-4644. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2009-4645 | Accellion Secure File Transfer Appliance 7 0 135 web_client_user_guide.html lang path traversal (EDB-33622 / XFDB-56246)
3 months ago
A vulnerability labeled as problematic has been found in Accellion Secure File Transfer Appliance 7 0 135. The impacted element is an unknown function of the file web_client_user_guide.html. The manipulation of the argument lang results in path traversal.
This vulnerability is cataloged as CVE-2009-4645. The attack may be launched remotely. Furthermore, there is an exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2009-4646 | Accellion Secure File Transfer Appliance Administrative Web Interface code injection (SA38538)
3 months ago
A vulnerability marked as critical has been reported in Accellion Secure File Transfer Appliance. This affects an unknown function of the component Administrative Web Interface. This manipulation causes code injection.
This vulnerability is registered as CVE-2009-4646. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2009-4647 | Accellion Secure File Transfer Appliance 7 0 135 Audit Log Username cross site scripting (XFDB-56247 / BID-38176)
3 months ago
A vulnerability described as problematic has been identified in Accellion Secure File Transfer Appliance 7 0 135. This impacts an unknown function of the component Audit Log. Such manipulation of the argument Username leads to cross site scripting.
This vulnerability is documented as CVE-2009-4647. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2009-4648 | Accellion Secure File Transfer Appliance 7 0 135 access control (EDB-33623 / XFDB-56248)
3 months ago
A vulnerability classified as problematic has been found in Accellion Secure File Transfer Appliance 7 0 135. Affected is an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2009-4648. The attack requires a local approach. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-0108 | Symantec Client Security up to 3.0 ActiveX Control CLIproxy.dll SetRemoteComputerName memory corruption (Nessus ID 69956 / ID 117016)
3 months ago
A vulnerability, which was classified as critical, has been found in Symantec Client Security up to 3.0. Affected by this issue is the function SetRemoteComputerName in the library CLIproxy.dll of the component ActiveX Control. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2010-0108. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is advisable to upgrade the affected component.
vuldb.com