Aggregator
CVE-2024-32631 | ASR Falcon/Crane prior CP01.057.067 ciCCIOTOPT out-of-bounds
2 weeks 4 days ago
A vulnerability marked as critical has been reported in ASR Falcon and Crane. This vulnerability affects unknown code of the component ciCCIOTOPT. Performing manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2024-32631. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-32625 | ASR Falcon/Crane prior CP01.057.067 OffloadAMRWriter uninitialized variable
2 weeks 4 days ago
A vulnerability classified as problematic has been found in ASR Falcon and Crane. Impacted is an unknown function of the component OffloadAMRWriter. The manipulation leads to use of uninitialized variable.
This vulnerability is listed as CVE-2024-32625. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-32633 | ASR Falcon/Crane prior CP01.057.067 eMMC Full Disk Test expression is always false
2 weeks 4 days ago
A vulnerability classified as problematic was found in ASR Falcon and Crane. The affected element is an unknown function of the component eMMC Full Disk Test. The manipulation results in expression is always false.
This vulnerability is cataloged as CVE-2024-32633. An attack on the physical device is feasible. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-32634 | ASR Falcon CP01.057.063 dead code
2 weeks 4 days ago
A vulnerability, which was classified as problematic, has been found in ASR Falcon CP01.057.063. The impacted element is an unknown function. This manipulation causes dead code.
This vulnerability is registered as CVE-2024-32634. It is feasible to perform the attack on the physical device. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-4435 | dfinity ic-stable-structures up to 0.6.3 BTreeMap memory leak
2 weeks 4 days ago
A vulnerability, which was classified as problematic, was found in dfinity ic-stable-structures up to 0.6.3. Impacted is an unknown function of the component BTreeMap Handler. Such manipulation leads to memory leak.
This vulnerability is listed as CVE-2024-4435. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2022-50355 | Linux Kernel up to 6.0.2 staging initialization (Nessus ID 265486)
2 weeks 4 days ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.0.2. Affected by this vulnerability is an unknown functionality of the component staging. Executing manipulation can lead to improper initialization.
This vulnerability is handled as CVE-2022-50355. The attack can only be done within the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2022-50353 | Linux Kernel up to 6.1.1 mmc_add_host return value (Nessus ID 265666)
2 weeks 4 days ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.1. This affects the function mmc_add_host. The manipulation results in unchecked return value.
This vulnerability is cataloged as CVE-2022-50353. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2022-50354 | Linux Kernel up to 6.0.18/6.1.4 kfd_process_device_init_vm null pointer dereference (Nessus ID 265586)
2 weeks 4 days ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.0.18/6.1.4. This impacts the function kfd_process_device_init_vm. This manipulation causes null pointer dereference.
This vulnerability is registered as CVE-2022-50354. The attack requires access to the local network. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-32632 | ASR Falcon/Crane prior CP01.057.067 ATCMD function call with incorrect argument type
2 weeks 4 days ago
A vulnerability labeled as critical has been found in ASR Falcon and Crane. This affects an unknown part of the component ATCMD. Such manipulation leads to function call with incorrect argument type.
This vulnerability is referenced as CVE-2024-32632. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2023-29547 | Mozilla Firefox up to 111 Secure Cookie Remote Code Execution (Bug 1783536 / EUVD-2023-33089)
2 weeks 4 days ago
A vulnerability described as critical has been identified in Mozilla Firefox up to 111. Impacted is an unknown function of the component Secure Cookie Handler. Executing manipulation can lead to Remote Code Execution.
This vulnerability is registered as CVE-2023-29547. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-29543 | Mozilla Firefox up to 111 Debugging API use after free (Bug 1816158 / EUVD-2023-33085)
2 weeks 4 days ago
A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 111. Affected by this issue is some unknown functionality of the component Debugging API. The manipulation results in use after free.
This vulnerability is identified as CVE-2023-29543. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-29544 | Mozilla Firefox up to 111 Garbage Collector resource consumption (Bug 1818781 / EUVD-2023-33086)
2 weeks 4 days ago
A vulnerability identified as critical has been detected in Mozilla Firefox up to 111. This affects an unknown part of the component Garbage Collector. This manipulation causes resource consumption.
This vulnerability is tracked as CVE-2023-29544. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2022-50679 | Linux Kernel up to 5.10.151/5.15.75/6.0.5 net/core/xdp.c xdp_rxq_info_unreg allocation of resources (Nessus ID 278008)
2 weeks 4 days ago
A vulnerability was found in Linux Kernel up to 5.10.151/5.15.75/6.0.5. It has been declared as critical. This vulnerability affects the function xdp_rxq_info_unreg of the file net/core/xdp.c. Executing manipulation can lead to allocation of resources.
This vulnerability is tracked as CVE-2022-50679. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-50673 | Linux Kernel up to 6.1.3 ext4 ext4_inode_attach_jinode use after free (Nessus ID 278009)
2 weeks 4 days ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.3. This impacts the function ext4_inode_attach_jinode of the component ext4. Executing manipulation can lead to use after free.
This vulnerability appears as CVE-2022-50673. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-53860 | Linux Kernel up to 6.1.54/6.5.4 permission (Nessus ID 278010)
2 weeks 4 days ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.54/6.5.4. This vulnerability affects unknown code. The manipulation results in permission issues.
This vulnerability was named CVE-2023-53860. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
Bun and done: The second coming of the Shai-Hulud worm
2 weeks 4 days ago
Everything you need to know about npm compromises from Shai-Hulud’s latest campaign, including detection and prevention guidance
The Red Canary Team
Notepad++ 遭流量劫持,更新程序被植入恶意程序
2 weeks 4 days ago
Notepad++ 发布安全警告,它遭遇了流量劫持,部分地区的更新程序被植入恶意程序。调查发现,Notepad++ 更新程序 WinGUp 的流量被劫持到恶意服务器,下载恶意可执行文件。更新程序使用版本检查功能查询 URL“https://notepad-plus-plus.org/update/getDownloadUrl.php”并评估返回的 XML 文件。更新程序使用 XML 文件中列出的 Download-URL,将文件保存到 %TEMP% 文件夹并执行。任何能拦截和篡改此流量的攻击者都可以更改 Download-URL。Notepad++ v8.8.7 之前的版本使用了自签名证书,允许攻击者创建篡改后的更新并将其推送给受害者。从 v8.8.7 开始 Notepad++ 使用了来自 GlobalSign 签发的合法证书进行签名。
Over 644,000 Domains Exposed to Critical React Server Components Vulnerability
2 weeks 4 days ago
The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting React Server Components. Following significant improvements to their scanning methodologies, researchers have identified a massive attack surface comprising over 165,000 unique IP addresses and more than 644,000 domains hosting vulnerable code as of December 8, […]
The post Over 644,000 Domains Exposed to Critical React Server Components Vulnerability appeared first on Cyber Security News.
Guru Baran
CVE-2025-13072 | HandL UTM Grabber Tracker Plugin up to 2.8.0 on WordPress cross site scripting (EUVD-2025-202398)
2 weeks 4 days ago
A vulnerability identified as problematic has been detected in HandL UTM Grabber Tracker Plugin up to 2.8.0 on WordPress. The affected element is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-13072. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com