Aggregator
CVE-2024-42143 | Linux Kernel up to 6.9.8 orangefs_statfs out-of-bounds (Nessus ID 208951)
9 months 3 weeks ago
A vulnerability was suspected in Linux Kernel up to 6.9.8. This issue appears to be a false-positive. Please verify the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2024-41015 | Linux Kernel up to 6.10.1 ocfs2_check_dir_entry memory corruption (Nessus ID 208953)
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.10.1. This issue affects the function ocfs2_check_dir_entry. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2024-41015. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41017 | Linux Kernel up to 6.10.1 jfs Privilege Escalation (Nessus ID 208953)
9 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 6.10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component jfs. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-41017. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45732 | Splunk Enterprise/Cloud Platform prior 9.2.3/9.3.1 authorization (SVD-2024-1002 / Nessus ID 208956)
9 months 3 weeks ago
A vulnerability classified as critical has been found in Splunk Enterprise and Cloud Platform. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-45732. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44965 | Linux Kernel up to 6.10.4 pti_clone_pgtable stack-based overflow (Nessus ID 208953)
9 months 3 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.10.4. Affected by this vulnerability is the function pti_clone_pgtable. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-44965. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44968 | Linux Kernel up to 6.1.104/6.6.45/6.10.4/6.11-rc1 smp_processor_id Privilege Escalation (Nessus ID 208953)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.1.104/6.6.45/6.10.4/6.11-rc1 and classified as problematic. Affected by this issue is the function smp_processor_id. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-44968. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45005 | Linux Kernel up to 6.6.47/6.10.6 s390 virt_to_phys uninitialized pointer (051c0a558154/027ac3c50925/5a44bb061d04 / Nessus ID 208962)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.47/6.10.6 and classified as problematic. This issue affects the function virt_to_phys of the component s390. The manipulation leads to uninitialized pointer.
The identification of this vulnerability is CVE-2024-45005. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40907 | Linux Kernel up to 6.9.5 ionic_tx_clean denial of service (8812aa35f3e9/491aee894a08 / Nessus ID 208962)
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.9.5. It has been classified as critical. Affected is the function ionic_tx_clean. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-40907. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43864 | Linux Kernel up to 6.6.44/6.10.3 mlx5e allocation of resources (daab2cc17b6b/89064d09c56b/025f2b85a5e5 / Nessus ID 208962)
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.6.44/6.10.3. This affects an unknown part of the component mlx5e. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-43864. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-7690 | myfone Shopping 2.1.01.00.040 X.509 Certificate cryptographic issues (VU#582497)
9 months 3 weeks ago
A vulnerability classified as critical was found in myfone Shopping 2.1.01.00.040. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-7690. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2016-1370 | Cisco Prime Network Analysis Module up to 6.2 IPv6 Payload Length Calculator input validation (CSCuy37324 / ID 11679)
9 months 3 weeks ago
A vulnerability classified as problematic was found in Cisco Prime Network Analysis Module up to 6.2. Affected by this vulnerability is an unknown functionality of the component IPv6 Payload Length Calculator. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2016-1370. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
记一次因API接口问题导致目标内网沦陷
9 months 3 weeks ago
CVE-2019-19143 | TP-LINK TL-WR849N 0.9.1 Firmware cgi/softup POST Request improper authentication (ID 156586 / EDB-48152)
9 months 3 weeks ago
A vulnerability, which was classified as very critical, was found in TP-LINK TL-WR849N 0.9.1. This affects an unknown part of the file cgi/softup of the component Firmware Handler. The manipulation as part of POST Request leads to improper authentication.
This vulnerability is uniquely identified as CVE-2019-19143. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Congress Seeks Urgent Action After Chinese Telecom Hack
9 months 3 weeks ago
Lawmakers Demand Answers, Security Overhaul After Chinese Hack of Telecom Networks
Congress is demanding answers from AT&T, Verizon, and Lumen after reports revealed that Chinese hackers breached U.S. telecom infrastructure, targeting systems linked to court-authorized wiretaps, as the FBI and the Cybersecurity and Infrastructure Security Agency investigate the Salt Typhoon group.
Congress is demanding answers from AT&T, Verizon, and Lumen after reports revealed that Chinese hackers breached U.S. telecom infrastructure, targeting systems linked to court-authorized wiretaps, as the FBI and the Cybersecurity and Infrastructure Security Agency investigate the Salt Typhoon group.
Revenue Cycle Vendor Notifying 400,000 Patients of Hack
9 months 3 weeks ago
Texas-Based Gryphon Healthcare Says an Unnamed Third Party Was at Center of Breach
A Texas-based revenue cycle management firm is notifying about 400,000 individuals of a hacking incident it says originated with another third party. The incident is among a growing list of major breaches implicating vendors and cumulatively affecting tens of millions of patients so far this year.
A Texas-based revenue cycle management firm is notifying about 400,000 individuals of a hacking incident it says originated with another third party. The incident is among a growing list of major breaches implicating vendors and cumulatively affecting tens of millions of patients so far this year.
Oil and Gas Firms Aware of Cyber Risks
9 months 3 weeks ago
Sector Uses Multifactor, Eschews Cloud, Can't Afford Cyber Insurance
The oil and gas industry has high levels of cyber awareness and low levels of cyber insurance, says a sectoral assessment from credit rating agency Moody's. The sector has experienced a clutch of high-profile attacks including a high-profile 2021 incident at Colonial Pipeline.
The oil and gas industry has high levels of cyber awareness and low levels of cyber insurance, says a sectoral assessment from credit rating agency Moody's. The sector has experienced a clutch of high-profile attacks including a high-profile 2021 incident at Colonial Pipeline.
Most EU Nations to Miss Upcoming NIS2 Deadline
9 months 3 weeks ago
Only Six Nations Have Incorporated NIS2 Into National Statute
Most European countries are set to miss a trading bloc deadline for implementing a key cybersecurity regulation that requires measures such as mandatory security auditing for essential services such as hospitals and banks. Just six countries have integrated the NIS2 directive into national law.
Most European countries are set to miss a trading bloc deadline for implementing a key cybersecurity regulation that requires measures such as mandatory security auditing for essential services such as hospitals and banks. Just six countries have integrated the NIS2 directive into national law.
CVE-2014-7689 | Longluntan GzoneRC - The RC Hobby Hub 0.1 X.509 Certificate cryptographic issues (VU#582497)
9 months 3 weeks ago
A vulnerability classified as critical has been found in Longluntan GzoneRC - The RC Hobby Hub 0.1. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-7689. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2014-7688 | Home Improvement 0.1 X.509 Certificate cryptographic issues (VU#582497)
9 months 3 weeks ago
A vulnerability was found in Home Improvement 0.1. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-7688. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com