Aggregator
【补丁日速递】2025年2月微软补丁日安全风险通告
10 months ago
从31省政府工作报告洞察2025年网络与数据安全建设重点
10 months ago
报业集团被黑,近百家报纸印刷发行受影响
10 months ago
美国多州大量读者受影响
CVE-2021-20270 | Pygments up to 2.7.3 SMLLexer exception infinite loop (Nessus ID 215735)
10 months ago
A vulnerability was found in Pygments up to 2.7.3. It has been declared as problematic. This vulnerability affects unknown code of the component SMLLexer. The manipulation of the argument exception leads to infinite loop.
This vulnerability was named CVE-2021-20270. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-32614 | HDF5 up to 1.14.3 H5VM.c H5VM_memcpyvv memory corruption (Nessus ID 215738)
10 months ago
A vulnerability classified as critical has been found in HDF5 up to 1.14.3. This affects the function H5VM_memcpyvv of the file H5VM.c. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-32614. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-36023 | Linux Kernel up to 6.1.85/6.6.26/6.8.5 null pointer dereference (Nessus ID 215741)
10 months ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.85/6.6.26/6.8.5. This vulnerability affects unknown code. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-36023. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38664 | Linux Kernel up to 6.6.32/6.9.3 zynqmp_dpsub kernel/locking/mutex.c initialization (6ead3eccf67b/603661357056/be3f3042391d / Nessus ID 215753)
10 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.6.32/6.9.3. Affected by this vulnerability is an unknown functionality of the file kernel/locking/mutex.c of the component zynqmp_dpsub. The manipulation leads to improper initialization.
This vulnerability is known as CVE-2024-38664. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-30261 | nodejs Undici up to 5.28.3/6.0.0/6.11.0 fetch access control (GHSA-9qxr-qj54-h672 / Nessus ID 215771)
10 months ago
A vulnerability was found in nodejs Undici up to 5.28.3/6.0.0/6.11.0 and classified as problematic. Affected by this issue is the function fetch. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-30261. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-2253 | distribution API Request /v2/_catalog resource consumption (Nessus ID 215783)
10 months ago
A vulnerability was found in distribution. It has been declared as problematic. This vulnerability affects unknown code of the file /v2/_catalog of the component API Request Handler. The manipulation leads to resource consumption.
This vulnerability was named CVE-2023-2253. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2017-18214 | Moment Module up to 2.19.2 on Node.js Regular Expression resource consumption (Issue 4163 / Nessus ID 215799)
10 months ago
A vulnerability, which was classified as problematic, has been found in Moment Module up to 2.19.2 on Node.js. Affected by this issue is some unknown functionality of the component Regular Expression. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2017-18214. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-2879 | Google Go File Header Reader.Read resource consumption (FEDORA-2022-59a20edab2 / Nessus ID 215803)
10 months ago
A vulnerability was found in Google Go. It has been rated as problematic. This issue affects the function Reader.Read of the component File Header Handler. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2022-2879. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-32616 | HDF5 up to 1.14.3 H5Odtype.c H5O__dtype_encode_helper heap-based overflow (Nessus ID 215802)
10 months ago
A vulnerability classified as critical has been found in HDF5 up to 1.14.3. This affects the function H5O__dtype_encode_helper of the file H5Odtype.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-32616. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-46219 | cURL up to 8.4.0 HSTS File Name lib/fopen.c missing encryption (FEDORA-2023-2121eca964 / Nessus ID 215804)
10 months ago
A vulnerability, which was classified as problematic, was found in cURL up to 8.4.0. This affects an unknown part in the library lib/fopen.c of the component HSTS File Name Handler. The manipulation leads to missing encryption of sensitive data.
This vulnerability is uniquely identified as CVE-2023-46219. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-55577 | Dimensional Gate Linux Ratfor up to 1.06 stack-based overflow
10 months ago
A vulnerability, which was classified as critical, was found in Dimensional Gate Linux Ratfor up to 1.06. This affects an unknown part. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-55577. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-54142 | discourse-ai Post cross site scripting (GHSA-94c2-qr2h-88jv)
10 months ago
A vulnerability has been found in discourse-ai and classified as problematic. This vulnerability affects unknown code of the component Post Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-54142. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47605 | silverstripe-asset-admin up to 5.3.7 Shortcode cross site scripting (GHSA-7cmp-cgg8-4c82)
10 months ago
A vulnerability classified as problematic has been found in silverstripe-asset-admin up to 5.3.7. This affects an unknown part of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-47605. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Inline Hook 技术深度解析与应用
10 months ago
一、Inline Hook 技术原理1.1 Hook 技术分类在 Windows 系统中,Hook 技术主要分为两类:消息钩子:通过 SetWindowsHookEx拦截 GUI 消息代码级钩子:直接修改目标函数代码实现拦截Inline Hook(内联钩子)属于代码级钩子,其核心原理是通过修改目标函数入口处的指令,将其重定向到自定义函数,从而实现拦截和篡改。1.2 技术实现流程定位目标函数:获取函
元宵节 | 顺遂圆满,喜乐安康
10 months ago
工程中心祝您元宵节快乐,幸福“元”满
元宵节 | 顺遂圆满,喜乐安康
10 months ago
工程中心祝您元宵节快乐,幸福“元”满