Aggregator
.NET 内网攻防实战电子报刊
9 months 1 week ago
.NET 实战中使用 Sharp4FUAC 通过 Windows 白名单文件绕过 UAC 实现本地权限提升
9 months 1 week ago
字节启动新一轮股票回购,估值增至 3150 亿美元;雷军提议优化新能源车牌;北京举办首届人形机器人马拉松|极客早知道
9 months 1 week ago
苹果发布搭载 M3 芯片的新款 iPad Air,售价 4799 元起;
智谱发布 CogView4:首个支持生成汉字的开源文生图模型;
全球首款宠物智能手机亮相:支持定位、AI 实时通话
Weekly Report: JPCERT/CCが「JSAC2025 開催レポート DAY 1 」を公開
9 months 1 week ago
JPCERT/CCは、「JSAC2025 開催レポート DAY 1 」を公開しました。JSAC2025開催レポートは3回にわけてカンファレンスの様子を紹介します。第1回目となる本稿では、DAY 1 Main Trackの講演について紹介しています。
Daily Dose of Dark Web Informer - March 4th, 2025
9 months 1 week ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
当前最猖獗的12大勒索软件组织
9 months 1 week ago
勒索软件威胁正席卷全球,RaaS模式和双倍勒索策略加剧了攻击。LockBit、BlackCat等组织对全球企业构成严重风险,网络安全形势紧迫。
From Event to Insight: Unpacking a B2B Business Email Compromise (BEC) Scenario
9 months 1 week ago
Trend Micro™ Managed XDR assisted in an investigation of a B2B BEC attack that unveiled an entangled mesh weaved by the threat actor with the help of a compromised server, ensnaring three business partners in a scheme that spanned for days. This article features investigation insights, a proposed incident timeline, and recommended security practices.
Jay Yaneza
威努特零信任:筑牢高校信息系统安全访问的铜墙铁壁
9 months 1 week ago
为高校的数字化转型与信息安全建设奠定坚实基础。
VMware fixed three actively exploited zero-days in ESX products
9 months 1 week ago
Broadcom has addressed three VMware zero-day vulnerabilities in ESX products that are actively exploited in the wild. Broadcom released security updates to address three VMware zero-day vulnerabilities in ESX products that are actively exploited in the wild. The flaws, respectively tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, impact multiple VMware ESX products, including VMware ESXi, vSphere, […]
Pierluigi Paganini
CVE-2017-12457 | GNU binutils up to 2.29 libbfd section.c bfd_make_section_with_flags null pointer dereference (Nessus ID 220400 / ID 277638)
9 months 1 week ago
A vulnerability classified as problematic was found in GNU binutils up to 2.29. This vulnerability affects the function bfd_make_section_with_flags of the file section.c of the component libbfd. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2017-12457. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2017-12666 | ImageMagick 7.0.6-2 coders/inline.c WriteINLINEImage memory corruption (Nessus ID 220426 / BID-100226)
9 months 1 week ago
A vulnerability, which was classified as problematic, has been found in ImageMagick 7.0.6-2. This issue affects the function WriteINLINEImage of the file coders/inline.c. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2017-12666. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2017-11331 | Xiph.Org vorbis-tools 1.4.0 WAV File oggenc/audio.c wav_open memory corruption (EDB-42397 / Nessus ID 220402)
9 months 1 week ago
A vulnerability was found in Xiph.Org vorbis-tools 1.4.0 and classified as problematic. Affected by this issue is the function wav_open of the file oggenc/audio.c of the component WAV File Handler. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-11331. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-11190 | unrar-free 0.0.1 Debug Log Mode unrarlib.c memory corruption (Nessus ID 220465)
9 months 1 week ago
A vulnerability was found in unrar-free 0.0.1. It has been declared as critical. This vulnerability affects unknown code in the library unrarlib.c of the component Debug Log Mode. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-11190. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2017-11540 | ImageMagick 7.0.6-1 coders/xpm.c GetPixelIndex memory corruption (Issue 581 / Nessus ID 220464)
9 months 1 week ago
A vulnerability was found in ImageMagick 7.0.6-1 and classified as critical. This issue affects the function GetPixelIndex of the file coders/xpm.c. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2017-11540. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2017-12455 | GNU binutils up to 2.29 libbfd vms-alpha.c evax_bfd_print_emh out-of-bounds (Nessus ID 220453 / ID 277638)
9 months 1 week ago
A vulnerability was found in GNU binutils up to 2.29. It has been rated as critical. Affected by this issue is the function evax_bfd_print_emh of the file vms-alpha.c of the component libbfd. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2017-12455. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2017-10140 | Oracle Berkeley DB up to 6.1.37 Data Store access control (Nessus ID 220439 / ID 370625)
9 months 1 week ago
A vulnerability was found in Oracle Berkeley DB up to 6.1.37. It has been declared as critical. This vulnerability affects unknown code of the component Data Store. The manipulation leads to improper access controls.
This vulnerability was named CVE-2017-10140. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-12169 | FreeIPA 4.2.0 Password Hash information disclosure (Bug 1487697 / Nessus ID 220483)
9 months 1 week ago
A vulnerability has been found in FreeIPA 4.2.0 and classified as problematic. This vulnerability affects unknown code of the component Password Hash. The manipulation leads to information disclosure.
This vulnerability was named CVE-2017-12169. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2017-14108 | GNOME gedit up to 3.22.1 libgedit.a resource management (Issue 143983 / Nessus ID 220559)
9 months 1 week ago
A vulnerability classified as problematic was found in GNOME gedit up to 3.22.1. This vulnerability affects unknown code of the file libgedit.a. The manipulation with the input $software_input_value leads to improper resource management.
This vulnerability was named CVE-2017-14108. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2017-14857 | Exiv2 0.26 image.cpp Image use after free (Nessus ID 220543)
9 months 1 week ago
A vulnerability classified as problematic has been found in Exiv2 0.26. Affected is the function Image of the file image.cpp. The manipulation leads to use after free.
This vulnerability is traded as CVE-2017-14857. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com