Aggregator
CVE-2018-11776 | Oracle Enterprise Manager Base Platform 13.3.0.0/13.4.0.0 Reporting Framework input validation (EDB-45260 / ID 316314)
6 months 4 weeks ago
A vulnerability was found in Oracle Enterprise Manager Base Platform 13.3.0.0/13.4.0.0. It has been declared as critical. This vulnerability affects unknown code of the component Reporting Framework. The manipulation leads to improper input validation.
This vulnerability was named CVE-2018-11776. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2004-0083 | XFree86 up to 4.3.0 ReadFontAlias memory corruption (VU#820006 / EDB-23682)
6 months 4 weeks ago
A vulnerability was found in XFree86 up to 4.3.0. It has been classified as critical. Affected is the function ReadFontAlias. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2004-0083. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12667 | InvoicePlane up to 1.6.1 /invoices/view session expiration
6 months 4 weeks ago
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration.
This vulnerability is handled as CVE-2024-12667. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
It is recommended to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
vuldb.com
CVE-2024-35250 | Microsoft Windows up to Server 2022 23H2 Kernel-Mode Driver untrusted pointer dereference
6 months 4 weeks ago
A vulnerability was found in Microsoft Windows. It has been declared as critical. This vulnerability affects unknown code of the component Kernel-Mode Driver. The manipulation leads to untrusted pointer dereference.
This vulnerability was named CVE-2024-35250. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
How long does a uk phone number stay in quarantine before it gets released and is there a way to know when ?
6 months 4 weeks ago
iOS 18新安全机制引发的意外问题:我的备用机无法长期稳定转发短信
6 months 4 weeks ago
CNVD漏洞周报2024年第50期
6 months 4 weeks ago
2024年12月09日-2024年12月15日本周漏洞态势研判情况本周信息安全漏洞威胁整体评价级别为中。国家信息安全漏洞共享平台(以下简称CNVD)本周共收集、整理信息安全漏洞295个,其中高危漏洞1
上周关注度较高的产品安全漏洞(20241209-20241215)
6 months 4 weeks ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
上周关注度较高的产品安全漏洞(20241209-20241215)
6 months 4 weeks ago
CNVD漏洞周报2024年第50期
6 months 4 weeks ago
谛听 工控安全月报 | 11月
6 months 4 weeks ago
11月│月报 谛听工控安全月报上线了,工信部的最新政策,11月发生的多起工控安全事件,谛听团队收集的最新攻击教据......更多安全资讯,请关注“谛听ditecting",每月更新!
谛听 工控安全月报 | 11月
6 months 4 weeks ago
11月│月报 谛听工控安全月报上线了,工信部的最新政策,11月发生的多起工控安全事件,谛听团队收集的最新攻击教据......更多安全资讯,请关注“谛听ditecting",每月更新!
谛听 工控安全月报 | 11月
6 months 4 weeks ago
11月│月报 谛听工控安全月报上线了,工信部的最新政策,11月发生的多起工控安全事件,谛听团队收集的最新攻击教据......更多安全资讯,请关注“谛听ditecting",每月更新!
谛听 工控安全月报 | 11月
6 months 4 weeks ago
11月│月报 谛听工控安全月报上线了,工信部的最新政策,11月发生的多起工控安全事件,谛听团队收集的最新攻击教据......更多安全资讯,请关注“谛听ditecting",每月更新!
谛听 工控安全月报 | 11月
6 months 4 weeks ago
01中国信息通信研究院发布《新通话安全技术研究报告(2024年) 》11月7日,中国信息通信研究院(信通院)发布《新通话安全技术研究报告(2024 年)》(以下简称《报告》)。新通话是传统通话业务的创
European Union Sanctions Russian Malicious Cyber Actors
6 months 4 weeks ago
Trading Bloc Includes Doppelganger Actors and GRU Unit 29155 in Sanctions List
The European Union sanctioned Russian intelligence hackers and two Kremlin officials responsible for digital disinformation campaigns in an action the European Council said marked its first ever imposition of restrictive measures against Russian actors for hybrid activities
The European Union sanctioned Russian intelligence hackers and two Kremlin officials responsible for digital disinformation campaigns in an action the European Council said marked its first ever imposition of restrictive measures against Russian actors for hybrid activities
CISA Urges Enhanced Coordination in Incident Response Plan
6 months 4 weeks ago
Draft National Response Plan Offers Flexible Coordination Strategies Across Sectors
A draft update to the National Cyber Incident Response Plan aims to enhance federal coordination with both the public and private sectors to better address significant cyber incidents, establishing clear roles for federal cyber entities and emphasizing efficient threat response measures.
A draft update to the National Cyber Incident Response Plan aims to enhance federal coordination with both the public and private sectors to better address significant cyber incidents, establishing clear roles for federal cyber entities and emphasizing efficient threat response measures.
Winnti-Like Glutton Backdoor Targets Cybercriminals
6 months 4 weeks ago
Malware Exploits Cybercrime Ecosystem for Profit
Hackers are using a variant of a backdoor that's the hallmark of a Chinese threat actor suspected of ties to Beijing in order to target the cybercriminal underground. The malware t "shares near-complete similarity" with the a backdoor exclusively used by the Winnti Group.
Hackers are using a variant of a backdoor that's the hallmark of a Chinese threat actor suspected of ties to Beijing in order to target the cybercriminal underground. The malware t "shares near-complete similarity" with the a backdoor exclusively used by the Winnti Group.
Arctic Wolf to Buy Cylance for $160M to Boost AI-Driven XDR
6 months 4 weeks ago
Deal With BlackBerry Integrates EDR for Hybrid XDR Platform for Midmarket Customers
Arctic Wolf is acquiring Cylance from BlackBerry for $160 million to integrate its AI-driven EDR technology into a hybrid XDR tool. The move aims to streamline cybersecurity for midmarket companies by combining services with product offerings, cutting operational complexity and boosting scalability.
Arctic Wolf is acquiring Cylance from BlackBerry for $160 million to integrate its AI-driven EDR technology into a hybrid XDR tool. The move aims to streamline cybersecurity for midmarket companies by combining services with product offerings, cutting operational complexity and boosting scalability.