Aggregator
.NET 内网攻防实战电子报刊
8 months 3 weeks ago
01.NET内网安全攻防报刊小报童电子报刊【.NET内网安全攻防】也正式上线了,引入小报童也是为了弥补知识星球
.NET 四种方法上传 web.config 绕过限制实现RCE
8 months 3 weeks ago
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 3 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 3 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 3 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 3 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 3 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 3 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
CVE-2023-22630 | IzyBat Orange Casiers prior 20221102_1 getCasier.php taille sql injection (GHSA-j94f-5cg6-6j9j)
8 months 3 weeks ago
A vulnerability classified as critical was found in IzyBat Orange Casiers. This vulnerability affects unknown code of the file getCasier.php. The manipulation of the argument taille leads to sql injection.
This vulnerability was named CVE-2023-22630. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-23560 | Lexmark Product up to 2023-01-12 server-side request forgery
8 months 3 weeks ago
A vulnerability was found in Lexmark Product up to 2023-01-12. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2023-23560. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2022-31706 | VMware vRealize Log Insight path traversal (VMSA-2023-0001)
8 months 3 weeks ago
A vulnerability classified as critical has been found in VMware vRealize Log Insight. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2022-31706. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-31704 | VMware vRealize Log Insight access control (VMSA-2023-0001)
8 months 3 weeks ago
A vulnerability classified as critical was found in VMware vRealize Log Insight. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2022-31704. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-18329 | Rehau Device Configuration Interface permissions
8 months 3 weeks ago
A vulnerability was found in Rehau Device. It has been declared as very critical. This vulnerability affects unknown code of the component Configuration Interface. The manipulation leads to preservation of permissions.
This vulnerability was named CVE-2020-18329. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2022-20235 | Google Android PowerVR GPU Kernel Driver memory corruption (A-259967780)
8 months 3 weeks ago
A vulnerability classified as critical has been found in Google Android. Affected is an unknown function of the component PowerVR GPU Kernel Driver. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2022-20235. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-20458 | Google Android 12.0 CarNotificationListener.java StatusBarNotification.getKey log file (A-205567776)
8 months 3 weeks ago
A vulnerability was found in Google Android 12.0. It has been declared as problematic. Affected by this vulnerability is the function StatusBarNotification.getKey of the file CarNotificationListener.java. The manipulation leads to sensitive information in log files.
This vulnerability is known as CVE-2022-20458. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2018-25078 | mandb up to 2.8.4 on Gentoo /usr/bin/mandb incorrect execution-assigned permissions
8 months 3 weeks ago
A vulnerability was found in mandb up to 2.8.4 on Gentoo and classified as critical. Affected by this issue is some unknown functionality of the file /usr/bin/mandb. The manipulation leads to incorrect execution-assigned permissions.
This vulnerability is handled as CVE-2018-25078. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-20456 | Google Android 10.0/11.0/12.0/13.0 AutomaticZenRule.java AutomaticZenRule allocation of resources (A-242703780)
8 months 3 weeks ago
A vulnerability was found in Google Android 10.0/11.0/12.0/13.0. It has been declared as problematic. This vulnerability affects the function AutomaticZenRule of the file AutomaticZenRule.java. The manipulation leads to allocation of resources.
This vulnerability was named CVE-2022-20456. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-20489 | Google Android 10.0/11.0/12.0/13.0 AutomaticZenRule.java allocation of resources (A-242703460)
8 months 3 weeks ago
A vulnerability was found in Google Android 10.0/11.0/12.0/13.0. It has been rated as problematic. This issue affects some unknown processing of the file AutomaticZenRule.java. The manipulation leads to allocation of resources.
The identification of this vulnerability is CVE-2022-20489. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-20213 | Google Android 10.0/11.0/12.0 AndroidManifest.xml ApplicationsDetailsActivity denial of service (A-183410508)
8 months 3 weeks ago
A vulnerability was found in Google Android 10.0/11.0/12.0 and classified as problematic. Affected by this issue is the function ApplicationsDetailsActivity of the file AndroidManifest.xml. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2022-20213. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com