Aggregator
关键远程代码执行缺陷击中Lexmark打印机
9 months ago
安全客
NIST's 'LEV' Equation to Determine Likelihood a Bug Was Exploited
9 months ago
The new 'Likely Exploited Vulnerabilities' metric could be a game-changer for SecOps teams and vulnerability patch prioritization.
Alexander Culafi, Senior News Writer, Dark Reading
【资料】美国国防部和情报部门向国会隐瞒异常现象信息
9 months ago
2023年,一位名叫大卫·格鲁什的前高级情报官员在国会作证称,有人告诉他美国政府已经回收了非人类起源的飞行器和生物材料。
谷歌推出每月249.99美元的AI Ultra订阅
9 months ago
安全客
Pwn 2Own柏林回顾:VMware收件箱、Windows 11遭零日黑客攻击
9 months ago
安全客
帕洛阿尔托网络公司警告XSS漏洞,并使用SEARCH漏洞代码
9 months ago
安全客
Нет приложения — нет Москвы: мигрантам придётся жить по координатам GPS
9 months ago
Отпечатки, селфи, адрес, слежка — с 1 сентября это обязательный чек-лист для въезда в столицу.
硬核守护!360解密两大高危勒索软件,助力用户夺回“数据主权”获致谢。
9 months ago
安全客
Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs
9 months ago
A Google Chrome Web Store campaign uses over 100 malicious browser extensions that mimic legitimate tools, such as VPNs, AI assistants, and crypto utilities, to steal browser cookies and execute remote scripts secretly. [...]
Bill Toulas
‘Deep concern’ for domestic abuse survivors as cybercriminals expected to publish confidential refuge addresses
9 months ago
A data extortion incident impacting the British government’s Legal Aid Agency could have serious implications for vulnerable people.
Alleged Sale of Shell Access to an Unidentified Company in Germany
9 months ago
Alleged Sale of Shell Access to an Unidentified Company in Germany
Dark Web Informer - Cyber Threat Intelligence
Flaw in Google Cloud Functions Sparks Broader Security Concerns
9 months ago
Patched privilege escalation flaw in Google Cloud Platform linked to wider cloud security concerns
BSidesLV24 – GroundFloor – Insert Coin: Hacking Arcades For Fun
9 months ago
Authors/Presenters: Ignacio Navarro
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – GroundFloor – Insert Coin: Hacking Arcades For Fun appeared first on Security Boulevard.
Marc Handelman
CVE-2020-8622 | ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1 TSIG Response assertion (Nessus ID 236577)
9 months ago
A vulnerability classified as problematic has been found in ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1. This affects an unknown part of the component TSIG Handler. The manipulation as part of Response leads to reachable assertion.
This vulnerability is uniquely identified as CVE-2020-8622. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-8623 | ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1 PKCS11 denial of service (Nessus ID 236577)
9 months ago
A vulnerability classified as problematic was found in ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1. This vulnerability affects unknown code of the component PKCS11 Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2020-8623. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-8622 | Oracle Communications Diameter Signaling Router up to 8.5.0.0 BIND denial of service (Nessus ID 236577)
9 months ago
A vulnerability was found in Oracle Communications Diameter Signaling Router up to 8.5.0.0. It has been declared as critical. This vulnerability affects unknown code of the component BIND. The manipulation leads to denial of service.
This vulnerability was named CVE-2020-8622. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13313 | libosinfo 1.5.0 osinfo-install-script Credentials credentials management (RHSA-2019:3387 / Nessus ID 236578)
9 months ago
A vulnerability was found in libosinfo 1.5.0 and classified as problematic. Affected by this issue is some unknown functionality of the component osinfo-install-script. The manipulation leads to credentials management (Credentials).
This vulnerability is handled as CVE-2019-13313. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2019-6465 | ISC BIND Zone Transfer permission assignment (RHSA-2019:3552 / Nessus ID 236577)
9 months ago
A vulnerability, which was classified as critical, has been found in ISC BIND up to 9.10.8-P1/9.11.5-P2/9.11.5-S3/9.12.3-P2/9.13.6. This issue affects some unknown processing of the component Zone Transfer Handler. The manipulation leads to incorrect permission assignment.
The identification of this vulnerability is CVE-2019-6465. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-6471 | ISC BIND up to 9.15.0 dispatch.c Malformed Packet race condition (K10092301 / Nessus ID 236577)
9 months ago
A vulnerability was found in ISC BIND up to 9.15.0. It has been classified as problematic. This affects an unknown part of the file dispatch.c. The manipulation as part of Malformed Packet leads to race condition.
This vulnerability is uniquely identified as CVE-2019-6471. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com