Aggregator
CVE-2003-1308 | fvwm 2.4.17/2.5.8 fvwm-menu-directory privileges management (EDB-23414 / BID-9161)
8 months 3 weeks ago
A vulnerability was found in fvwm 2.4.17/2.5.8. It has been declared as problematic. This vulnerability affects unknown code of the file fvwm-menu-directory. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2003-1308. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DEF CON 32 – AppSec Village – Defeating Secure Code Review GPT Hallucinations
8 months 3 weeks ago
Authors/Presenters:Wang Zhilong, Xinzhi Luo
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their timely DEF CON 32 erudite content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – AppSec Village – Defeating Secure Code Review GPT Hallucinations appeared first on Security Boulevard.
Marc Handelman
【知道创宇404实验室】警惕CVE-2024-47575针对Fortinet FortiManager的认证绕过漏洞
8 months 3 weeks ago
How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50%
8 months 3 weeks ago
The post How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50% appeared first on Strobes Security.
The post How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50% appeared first on Security Boulevard.
strobes
CVE-2021-20193 | GNU Tar up to 1.33 Input File src/list.c memory leak
8 months 3 weeks ago
A vulnerability was found in GNU Tar up to 1.33. It has been rated as problematic. Affected by this issue is some unknown functionality of the file src/list.c of the component Input File Handler. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2021-20193. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-43701 | ARM Compiler 5 Installation default permission
8 months 3 weeks ago
A vulnerability has been found in ARM Compiler 5, Compiler 6, Compiler for Embedded, Compiler for Embedded FuSa, Compiler for Linux, Development Studio, Development Studio Morello Edition, Forge, Mobile Studio, DS-5 Development Studio, Fast Models, GNU Toolchain, Installer Vulnerabilities, Keil MDK and Socrates and classified as critical. Affected by this vulnerability is an unknown functionality of the component Installation. The manipulation leads to incorrect default permissions.
This vulnerability is known as CVE-2022-43701. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-49029 | Linux Kernel up to 6.0.11 drivers/hwmon/ibmpex.c ibmpex_register_bmc use after free
8 months 3 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.0.11. Affected by this vulnerability is the function ibmpex_register_bmc of the file drivers/hwmon/ibmpex.c. The manipulation leads to use after free.
This vulnerability is known as CVE-2022-49029. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49028 | Linux Kernel up to 5.10.157/5.15.81/6.0.11 ixgbevf_init_module memory leak
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.157/5.15.81/6.0.11. Affected is the function ixgbevf_init_module. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2022-49028. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49014 | Linux Kernel up to 4.19.267/5.4.225/5.10.157/5.15.81/6.0.11 tun_detach use after free
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 4.19.267/5.4.225/5.10.157/5.15.81/6.0.11. It has been classified as critical. This affects the function tun_detach. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2022-49014. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49016 | Linux Kernel up to 5.15.81/6.0.11 mdiobus of_node_get/of_node_put reference count (543d917f691a/2708b3574404/cdde1560118f)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.15.81/6.0.11. This issue affects the function of_node_get/of_node_put of the component mdiobus. The manipulation leads to improper update of reference count.
The identification of this vulnerability is CVE-2022-49016. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49018 | Linux Kernel up to 6.0.11 mptcp net/mptcp/protocol.c in_atomic stack-based overflow (d8e6c5500dbf/b4f166651d03)
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.0.11. Affected is the function in_atomic of the file net/mptcp/protocol.c of the component mptcp. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2022-49018. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49030 | Linux Kernel up to 5.10.157/5.15.81/6.0.11 libbpf max_entries buffer overflow
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 5.10.157/5.15.81/6.0.11. It has been classified as critical. Affected is the function max_entries of the component libbpf. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2022-49030. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49031 | Linux Kernel up to 6.0.11 afe4403_read_raw out-of-bounds
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.0.11. It has been declared as problematic. Affected by this vulnerability is the function afe4403_read_raw. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2022-49031. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49032 | Linux Kernel up to 6.0.11 afe4404_read_raw/afe4404_write_raw out-of-bounds
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.0.11. It has been rated as problematic. Affected by this issue is the function afe4404_read_raw/afe4404_write_raw. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2022-49032. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
优秀创新成果!360安全大模型再获权威肯定
8 months 3 weeks ago
360安全大模型获2024中国国际数字经济博览会优秀创新成果
石家庄市政府与360达成战略合作 树立全国数字经济创新发展标杆
8 months 3 weeks ago
石家庄市政府与360携手 助推河北省数字安全和人工智能产业升级
'Shift Left' Gets Pushback, Triggers Security Soul Searching
8 months 3 weeks ago
A government report's criticism of the 100x metric often used to justify fixing software earlier in development fuels a growing debate over pushing responsibility for secure code onto developers.
Robert Lemos, Contributing Writer
流程速览 | “工业征途 安全守护”工业领域数据安全实践与创新论坛
8 months 3 weeks ago
点击查看,预约参会。
中国网络安全市场营收攀升背后的驱动力与待解难题
8 months 3 weeks ago
Gartner预测安全软件、安全服务和网络安全领域将迎来显著增长。