Aggregator
收藏 | dotNet 安全矩阵团队2024年度内网横向移动阶段文章和工具汇总
10 months 2 weeks ago
CVE-2005-2175 | IBM Lotus Domino 5.x/6.x HTML Attachment information disclosure (EDB-25944 / BID-14164)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in IBM Lotus Domino 5.x/6.x. Affected by this issue is some unknown functionality of the component HTML Attachment Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2005-2175. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to replace the affected component with an alternative.
vuldb.com
CVE-2014-9147 | Fiyo CMS 2.0.1.8 Database Backup .backup/ Backup File information disclosure (EDB-36581 / BID-73437)
10 months 2 weeks ago
A vulnerability was found in Fiyo CMS 2.0.1.8. It has been classified as problematic. Affected is an unknown function of the file .backup/ of the component Database Backup. The manipulation as part of Backup File leads to information disclosure.
This vulnerability is traded as CVE-2014-9147. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2005-4502 | Net-square httprint 202 cross site scripting (EDB-26966 / XFDB-23885)
10 months 2 weeks ago
A vulnerability was found in Net-square httprint 202 and classified as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2005-4502. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-1669 | Barracuda Spam Firewall Zoo Archive denial of service (EDB-3851 / XFDB-34080)
10 months 2 weeks ago
A vulnerability classified as critical has been found in Barracuda Spam Firewall. Affected is an unknown function of the component Zoo Archive Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2007-1669. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-13102 | Gameloft Asphalt Xtreme: Offroad Rally Racing 1.6.0 on iOS hard-coded credentials (VU#787952)
10 months 2 weeks ago
A vulnerability was found in Gameloft Asphalt Xtreme: Offroad Rally Racing 1.6.0 on iOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to hard-coded credentials.
This vulnerability is known as CVE-2017-13102. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-13106 | Cheetahmobile CM Launcher 3D - Theme/Wallpaper/Secure/Efficient 5.0.3 on Android hard-coded credentials (VU#787952)
10 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Cheetahmobile CM Launcher 3D - Theme, Wallpaper, Secure and Efficient 5.0.3 on Android. This issue affects some unknown processing. The manipulation leads to hard-coded credentials.
The identification of this vulnerability is CVE-2017-13106. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2008-2462 | Caucho Resin up to 3.1.3 file cross site scripting (VU#305208 / Nessus ID 33273)
10 months 2 weeks ago
A vulnerability was found in Caucho Resin and classified as problematic. This issue affects some unknown processing. The manipulation of the argument file leads to cross site scripting.
The identification of this vulnerability is CVE-2008-2462. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-0104 | Microsoft Windows iSNS Server integer overflow (MS17-012 / Nessus ID 97743)
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Windows Server 2008 R2 SP1/Server 2008 SP2/Server 2012/Server 2012 R2/Server 2016. Affected is an unknown function of the component iSNS Server. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2017-0104. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-13101 | Musical.ly 6.1.6 on iOS hard-coded credentials (VU#787952)
10 months 2 weeks ago
A vulnerability was found in Musical.ly 6.1.6 on iOS. It has been classified as critical. Affected is an unknown function. The manipulation leads to hard-coded credentials.
This vulnerability is traded as CVE-2017-13101. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2016-4957 | ntpd up to 4.2.8p7 Crypto-NAK Packet valid_NAK input validation (VU#321640 / Nessus ID 91662)
10 months 2 weeks ago
A vulnerability has been found in ntpd up to 4.2.8p7 and classified as critical. This vulnerability affects the function valid_NAK of the component Crypto-NAK Packet Handler. The manipulation leads to improper input validation.
This vulnerability was named CVE-2016-4957. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2016-4956 | ntpd up to 4.2.8p7 Synchronization data processing (USN-3096-1 / VU#321640)
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in ntpd up to 4.2.8p7. This affects an unknown part of the component Synchronization. The manipulation leads to data processing error.
This vulnerability is uniquely identified as CVE-2016-4956. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2016-1897 | FFmpeg 2.x HTTP Live Stream M3U8 File information disclosure (USN-2944-1 / VU#772447)
10 months 2 weeks ago
A vulnerability was found in FFmpeg 2.x. It has been declared as problematic. This vulnerability affects unknown code of the component HTTP Live Stream Handler. The manipulation as part of M3U8 File leads to information disclosure.
This vulnerability was named CVE-2016-1897. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-1898 | FFmpeg 2.x HTTP Live Stream M3U8 File information disclosure (USN-2944-1 / VU#772447)
10 months 2 weeks ago
A vulnerability was found in FFmpeg 2.x. It has been rated as problematic. This issue affects some unknown processing of the component HTTP Live Stream Handler. The manipulation as part of M3U8 File leads to information disclosure.
The identification of this vulnerability is CVE-2016-1898. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-4955 | ntpd up to 4.2.8p7 Autokey race condition (USN-3096-1 / VU#321640)
10 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in ntpd up to 4.2.8p7. Affected by this issue is some unknown functionality of the component Autokey Handler. The manipulation leads to race condition.
This vulnerability is handled as CVE-2016-4955. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2015-2305 | Henry Spencer Regex Library on 32-bit regcomp numeric error (VU#695940 / Nessus ID 83494)
10 months 2 weeks ago
A vulnerability has been found in Henry Spencer Regex Library on 32-bit and classified as critical. Affected by this vulnerability is the function regcomp. The manipulation leads to numeric error.
This vulnerability is known as CVE-2015-2305. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2014-3566 | Oracle Endeca Server 7.4.0.0/7.5.0.0/7.5.1.0/7.6.0.0/7.6.1.0 OpenSSL cryptographic issues (VU#577193 / Nessus ID 79713)
10 months 2 weeks ago
A vulnerability was found in Oracle Endeca Server 7.4.0.0/7.5.0.0/7.5.1.0/7.6.0.0/7.6.1.0 and classified as problematic. This issue affects some unknown processing of the component OpenSSL. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-3566. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Sandfly 5.3 - Detailed Host Forensics and Microsoft Sentinel Integration
10 months 2 weeks ago
Product Update Linux Forensics Rootkits MalwareDateJanuary 26, 2025AuthorThe Sandfly Security TeamSa
NetSupport恶意软件实战分析
10 months 2 weeks ago
NetSupport恶意软件实战分析