Aggregator
CVE-2024-47732 | Linux Kernel up to 6.10.12/6.11.1 use after free (b5d534b473e2/c66f0be993ba/e0d3b845a1b1 / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.12/6.11.1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-47732. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50034 | Linux Kernel up to 6.11.3 icsk_syn_mss null pointer dereference (44dc50df15f5/6fd27ea183c2 / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.11.3. It has been classified as critical. Affected is the function icsk_syn_mss. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-50034. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47724 | Linux Kernel up to 6.10.12/6.11.1 on BSS wmi.c ath11k_wmi_p2p_go_bcn_ie Privilege Escalation (dbd51da69dda/6db232905e09/177b49dbf9c1 / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.10.12/6.11.1 on BSS. This issue affects the function ath11k_wmi_p2p_go_bcn_ie of the file drivers/net/wireless/ath/ath11k/wmi.c. The manipulation leads to Privilege Escalation.
The identification of this vulnerability is CVE-2024-47724. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50222 | Linux Kernel up to 6.6.59/6.11.6 iov_iter copy_page_from_iter_atomic infinite loop (4f7ffa83fa79/3a303409f271/c749d9b7ebbc / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.6.59/6.11.6. This issue affects the function copy_page_from_iter_atomic of the component iov_iter. The manipulation leads to infinite loop.
The identification of this vulnerability is CVE-2024-50222. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50092 | Linux Kernel up to 6.11.3 drivers/net/netconsole.c write_ext_msg iteration (712a3af37102/d94785bb46b6 / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.11.3. It has been declared as problematic. This vulnerability affects the function write_ext_msg of the file drivers/net/netconsole.c. The manipulation leads to excessive iteration.
This vulnerability was named CVE-2024-50092. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53080 | Linux Kernel up to 6.11.7 panthor heap-based overflow (3342f066a8e1/444fa5b100e5 / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.11.7. It has been rated as critical. Affected by this issue is some unknown functionality of the component panthor. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-53080. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47733 | Linux Kernel up to 6.10.12/6.11.1 netfs_init release of resource (603f95cefbee/7a9eaf97d566/3c58a9575e02 / Nessus ID 216493)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.10.12/6.11.1. It has been classified as problematic. This affects the function netfs_init. The manipulation leads to missing release of resource.
This vulnerability is uniquely identified as CVE-2024-47733. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
虚假认证网络安全合规,这家公司被罚1125万美元;Signal 、Line 和Gmail 被伪造成攻击工具,攻击中文用户 |牛览
9 months 3 weeks ago
新闻速览 •美国网络安全机构发布联合咨文,防范Ghost勒索软件攻击 •虚假认证网络安全合规,这家公司被罚11 […]
aqniu
隐形AI风险浮现:安全专家呼吁该治理“影子AI”了
9 months 3 weeks ago
网安领导者和CISO发现,近年来大量影子AI应用程序已危及企业网络,有些甚至持续运行一年多。 这些应用并非典型 […]
aqniu
新型CipherLocker勒索病毒样本分析
9 months 3 weeks ago
新型CipherLocker勒索病毒样本分析
通过 Sharp4SploitConsole2012 实现 Windows 2012 横向移动
9 months 3 weeks ago
.NET 内网攻防实战电子报刊
9 months 3 weeks ago
Sharp4PCA.exe:利用 Windows 系统白名单文件启动指定二进制文件进程的工具
9 months 3 weeks ago
阿里财报超预期,股价大涨 10%;B 站毛利增 68%,全面盈利;美知名机器人公司推具身智能模型|极客早知道
9 months 3 weeks ago
NVIDIA 免费放出全球最大基因研究 AI 系统:9 兆个基因信息;
OPPO Find N5 手机发布:打破全球最薄折叠旗舰纪录,8999 元起;
电影《哪吒之魔童闹海》海外票房破亿,北美开画影院达「史无前例」945 间
Daily Dose of Dark Web Informer - February 20th, 2025
9 months 3 weeks ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
警惕!AMOS伪装成DeepSeek窃取Mac用户数据
9 months 3 weeks ago
警惕!AMOS伪装成DeepSeek窃取Mac用户数据
9 months 3 weeks ago
警惕!AMOS伪装成DeepSeek窃取Mac用户数据
9 months 3 weeks ago
警惕!AMOS伪装成DeepSeek窃取Mac用户数据
9 months 3 weeks ago