Aggregator
2025第12周投资收益
8 months 4 weeks ago
2025第12周投资收益
2025第12周投资收益
8 months 4 weeks ago
2025第12周投资收益
2025第12周投资收益
8 months 4 weeks ago
2025第12周投资收益
2025第12周投资收益
8 months 4 weeks ago
2025第12周投资收益
2025第12周投资收益
8 months 4 weeks ago
2025第12周投资收益
2025第12周投资收益
8 months 4 weeks ago
2025第12周投资收益
2025第12周投资收益
8 months 4 weeks ago
2025第12周投资收益
Утечка Keenetic: хакеры получили ключи к миллиону домашних сетей россиян
8 months 4 weeks ago
Как уязвимость 2023 года привела к утечке в 2025-м.
CVE-2025-30474 | Apache Commons VFS up to 2.9.x FtpFileObject information exposure
8 months 4 weeks ago
A vulnerability was found in Apache Commons VFS up to 2.9.x. It has been declared as problematic. Affected by this vulnerability is the function FtpFileObject. The manipulation leads to information exposure through error message.
This vulnerability is known as CVE-2025-30474. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27553 | Apache Commons VFS up to 2.9.x FileObject API resolveFile Scope path traversal
8 months 4 weeks ago
A vulnerability was found in Apache Commons VFS up to 2.9.x. It has been classified as problematic. Affected is the function resolveFile of the component FileObject API. The manipulation of the argument Scope leads to relative path traversal.
This vulnerability is traded as CVE-2025-27553. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2691 | nossrf up to 1.0.3 Hostname server-side request forgery (SNYK-JS-NOSSRF-9510842)
8 months 4 weeks ago
A vulnerability was found in nossrf up to 1.0.3 and classified as critical. This issue affects some unknown processing. The manipulation of the argument Hostname leads to server-side request forgery.
The identification of this vulnerability is CVE-2025-2691. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0927 | Canonical Ubuntu Linux prior 6.11.0-18.18 HFS+ filesystem out-of-bounds write (USN-7276-1)
8 months 4 weeks ago
A vulnerability has been found in Canonical Ubuntu Linux and classified as critical. This vulnerability affects unknown code of the component HFS+ filesystem. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2025-0927. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SecWiki News 2025-03-23 Review
8 months 4 weeks ago
摧毁x86最后堡垒:Intel电熔丝e-Fuse加密密钥泄漏
8 months 4 weeks ago
Shawn C 写道:
Intel CSME(企业安全管理引擎)可以说是当前最复杂的带外平台之一,然而厂商对此并未提供足够的透明度。Mark Ermolov撰写的这篇出色文章深入揭示了其技术细节,这些细节源于多年的研究、调试和逆向工程。对于x86平台的系统安全防护而言,若不将Intel CSME或AMD PSP等原厂带外系统纳入威胁模型的构建,得出的结论必然会存在偏颇。CSME是“通过模糊性实现安全”的极端案例。自2015年以来,CSME本身提供了众多安全特性,但其内部机制却不透明,攻击者和安全研究人员只能依赖逆向工程和调试来进行研究。这种情况对研究人员而言充满挑战与乐趣,但对企业和个人的安全而言,却是教科书式的灾难。CSME的复杂性即使对大多数安全从业人员来说也依然难以捉摸,更不用说非安全领域的从业人员和普通用户。
换个角度来看,如果带外系统能够有开源实现,将极大减少信息不对称的风险。尽管开源本身带来的透明度并不一定直接转化为安全收益,但它无疑为安全研究提供了更为广阔的视野和更高的参与度。
换个角度来看,如果带外系统能够有开源实现,将极大减少信息不对称的风险。尽管开源本身带来的透明度并不一定直接转化为安全收益,但它无疑为安全研究提供了更为广阔的视野和更高的参与度。
前往美国最好带上一次性使用的手机
8 months 4 weeks ago
美国最高法院于 2014 年裁决,无搜查令搜查手机违反了宪法第四修正案,但边境或入境处搜查手机不属于违宪。理由是入境处如机场和边境的搜查属于美国国境之外的搜查,因此美国海关和边境保护局(CBP)等执法机构可以无搜查令搜查手机,并根据手机上的内容拒绝旅客入境。电子前哨基金会(EFF)的资深律师 Saira Hussain 指出,宪法第四修正案将边境搜查列为例外,其最初的设想是允许海关官员搜查行李之类的物品,因为你随身携带的任何东西都与旅行相关,搜查行李箱是为了寻找不允许入境的人或物。但今天的时代不同了,你随身携带的手机包含了你所有的隐私和秘密,不只是与旅行相关。Hussain 建议旅行者在美国入境时尽可能少的携带数据——也就是最好使用一次性的手机而不是你常用的手机。如果想继续使用自己的常用设备,那么最好将设备上的数据上传到云端,然后清空数据,将手机保持在飞行模式或关机。这么做只是降低在入境时面临的风险。CBP 如果真的想查看你的手机,他们还是可能会找到办法。
CVE-2019-8558 | Apple iCloud up to 7.10 on Windows WebKit memory corruption (HT209605 / EDB-46650)
8 months 4 weeks ago
A vulnerability was found in Apple iCloud up to 7.10 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component WebKit. The manipulation leads to memory corruption.
This vulnerability was named CVE-2019-8558. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34130 | Adobe Acrobat Mobile Sign up to 24.4.2.33155 on Android authorization (apsb24-50)
8 months 4 weeks ago
A vulnerability has been found in Adobe Acrobat Mobile Sign up to 24.4.2.33155 on Android and classified as problematic. This vulnerability affects unknown code. The manipulation leads to incorrect authorization.
This vulnerability was named CVE-2024-34130. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-2274 | PivotX up to 2.3.2 File cross site scripting (EDB-37146 / Nessus ID 59083)
8 months 4 weeks ago
A vulnerability classified as problematic was found in PivotX up to 2.3.2. This vulnerability affects unknown code. The manipulation of the argument File leads to cross site scripting.
This vulnerability was named CVE-2012-2274. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-36395 | Verint WFO prior 15.2.1030 cross site scripting
8 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Verint WFO. This issue affects some unknown processing. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2024-36395. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com