Aggregator
CVE-2017-0070 | Microsoft Edge 38.14393.0.0 Scripting Engine access control (MS17-007 / EDB-41623)
7 months ago
A vulnerability was found in Microsoft Edge 38.14393.0.0. It has been rated as critical. This issue affects some unknown processing of the component Scripting Engine. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2017-0070. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-0071 | Microsoft Edge Scripting Engine memory corruption (MS17-007 / Nessus ID 97730)
7 months ago
A vulnerability classified as critical has been found in Microsoft Edge. Affected is an unknown function of the component Scripting Engine. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2017-0071. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-0072 | Microsoft Windows Uniscribe data processing (MS17-011 / EDB-41654)
7 months ago
A vulnerability was found in Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2008 SP2/Vista SP2 and classified as critical. Affected by this issue is some unknown functionality of the component Uniscribe. The manipulation leads to data processing error.
This vulnerability is handled as CVE-2017-0072. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-0067 | Microsoft Edge Scripting Engine memory corruption (MS17-007 / Nessus ID 97730)
7 months ago
A vulnerability was found in Microsoft Edge and classified as critical. Affected by this issue is some unknown functionality of the component Scripting Engine. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-0067. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-0068 | Microsoft Edge information disclosure (MS17-007 / Nessus ID 97730)
7 months ago
A vulnerability was found in Microsoft Edge. It has been classified as problematic. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2017-0068. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-0069 | Microsoft Edge input validation (MS17-007 / Nessus ID 97730)
7 months ago
A vulnerability was found in Microsoft Edge. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to improper input validation.
This vulnerability was named CVE-2017-0069. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-0066 | Microsoft Edge Security Feature access control (MS17-007 / Nessus ID 97730)
7 months ago
A vulnerability has been found in Microsoft Edge and classified as critical. Affected by this vulnerability is an unknown functionality of the component Security Feature. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2017-0066. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Adobe security advisory (AV24–729)
7 months ago
Canadian Centre for Cyber Security
CVE-2004-0989 | libxml2 DNS Reply xmlNanoFTPConnect memory corruption (EDB-24704 / Nessus ID 38061)
7 months ago
A vulnerability classified as critical was found in libxml2. Affected by this vulnerability is the function xmlNanoFTPConnect of the component DNS Reply Handler. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2004-0989. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
These are the cybersecurity stories we were jealous of in 2024
7 months ago
Since 2018, along with colleagues first at VICE Motherboard, and now at TechCrunch, I have been pub
CVE-2013-5566 | Cisco NX-OS up to 4.1.x memory corruption (Alert 31663 / Nessus ID 78557)
7 months ago
A vulnerability classified as problematic has been found in Cisco NX-OS up to 4.1.x. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2013-5566. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2013-5560 | Cisco ASA up to 9.1.3 IPv6 Network Address Translation IPv6 Packet input validation (ID 43396 / XFDB-88652)
7 months ago
A vulnerability was found in Cisco ASA up to 9.1.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component IPv6 Network Address Translation Handler. The manipulation as part of IPv6 Packet leads to improper input validation.
This vulnerability is handled as CVE-2013-5560. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-5557 | Cisco ASA 9.1(.2) Proxy Content Rewriter code (CSCug91577 / ID 43473)
7 months ago
A vulnerability was found in Cisco ASA 9.1(.2). It has been declared as problematic. This vulnerability affects unknown code of the component Proxy Content Rewriter. The manipulation leads to code.
This vulnerability was named CVE-2013-5557. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2013-5576 | Joomla CMS 2.5.13/3.1.4 File Upload media.php PHP File input validation (VU#639620 / EDB-27610)
7 months ago
A vulnerability classified as critical was found in Joomla CMS 2.5.13/3.1.4. Affected by this vulnerability is an unknown functionality of the file administrator/components/com_media/helpers/media.php of the component File Upload. The manipulation as part of PHP File leads to improper input validation.
This vulnerability is known as CVE-2013-5576. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-5648 | iD libdigidoc 3.6.0.0 Parser DigiDocSAXParser.c handleStartDataFile path traversal (Nessus ID 69549 / ID 122984)
7 months ago
A vulnerability was found in iD libdigidoc 3.6.0.0. It has been rated as critical. This issue affects the function handleStartDataFile of the file DigiDocSAXParser.c of the component Parser. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2013-5648. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Question
7 months ago
商用茶包会释放出数百万微塑料
7 months ago
根据发表在《Chemosphere》期刊上的一项研究,基于聚合物的商用茶包会在泡茶时释放出数以十亿计的纳米塑料和微塑料。这些塑料颗粒能被人体肠道细胞吸收,进入血液,可能影响人体健康。研究针对的茶包用聚合物尼龙-6、聚丙烯和纤维素制造,泡茶时聚丙烯每毫升释放约 12 亿个颗粒,平均大小 136.7 纳米;纤维素每毫升释放约 1.35 亿个颗粒,平均大小 244 纳米;尼龙-6 每毫升释放 818 万个颗粒,平均大小 138.4 纳米。生物相互作用实验显示,肠道细胞对微塑料和纳米塑料的吸收率最高,这些颗粒甚至能进入细胞核。
Best of 2024: An Accidental Discovery of a Backdoor Likely Prevented Thousands of Infections
7 months ago
... Read more »
The post An Accidental Discovery of a Backdoor Likely Prevented Thousands of Infections appeared first on Deepfactor.
The post Best of 2024: An Accidental Discovery of a Backdoor Likely Prevented Thousands of Infections appeared first on Security Boulevard.
Mike Larkin
Best of 2024: An Accidental Discovery of a Backdoor Likely Prevented Thousands of Infections
7 months ago
Yesterday’s discovery of the xz backdoor was an accident. But what a fortunate accident it was.