Aggregator
CVE-2008-3610 | Apple Mac OS X up to 10.5 Password Authentication improper authentication (Nessus ID 34211 / ID 115955)
10 months ago
A vulnerability classified as critical was found in Apple Mac OS X up to 10.5. This vulnerability affects unknown code of the component Password Authentication. The manipulation leads to improper authentication.
This vulnerability was named CVE-2008-3610. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-3609 | Apple Mac OS X up to 10.5 access control (Nessus ID 34211 / ID 115955)
10 months ago
A vulnerability classified as critical has been found in Apple Mac OS X up to 10.5. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2008-3609. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-6276 | Apple Mac OS X Server up to 10.5.0 accept_connections numeric error (EDB-4690 / Nessus ID 33281)
10 months ago
A vulnerability, which was classified as critical, has been found in Apple Mac OS X Server up to 10.5.0. This issue affects the function accept_connections. The manipulation leads to numeric error.
The identification of this vulnerability is CVE-2007-6276. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-3383 | Apache Tomcat up to 4.1.36 Error Message sendmail.jsp mailfrom cross site scripting (VU#862600 / Nessus ID 25995)
10 months ago
A vulnerability was found in Apache Tomcat and classified as problematic. This issue affects some unknown processing of the file sendmail.jsp of the component Error Message Handler. The manipulation of the argument mailfrom leads to basic cross site scripting.
The identification of this vulnerability is CVE-2007-3383. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2008-5082 | Red Hat Dogtag Certificate System up to 1.0 verifyProof improper authentication (ID 116166 / XFDB-48331)
10 months ago
A vulnerability was found in Red Hat Dogtag Certificate System up to 1.0. It has been declared as critical. Affected by this vulnerability is the function verifyProof. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2008-5082. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2008-2368 | Red Hat Certificate System 7.2 Installer credentials management (ID 116166 / XFDB-48022)
10 months ago
A vulnerability, which was classified as problematic, was found in Red Hat Certificate System 7.2. This affects an unknown part of the component Installer. The manipulation leads to credentials management.
This vulnerability is uniquely identified as CVE-2008-2368. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2019-6545 | AVEVA InduSoft Web Studio/InTouch Edge HMI Database Connection resource injection (EDB-46342 / ID 371636)
10 months ago
A vulnerability, which was classified as critical, was found in AVEVA InduSoft Web Studio and InTouch Edge HMI. This affects an unknown part of the component Database Connection. The manipulation leads to improper control of resource identifiers.
This vulnerability is uniquely identified as CVE-2019-6545. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Achieving Data Privacy Regulation Compliance in 2025 Frameworks
10 months ago
As we progress through 2025, organizations worldwide face an increasingly intricate web of data privacy regulations. With new laws taking effect across multiple jurisdictions and existing frameworks becoming more stringent, achieving compliance has never been more challenging or essential. Companies must adapt quickly to avoid hefty penalties while maintaining consumer trust in an era where […]
The post Achieving Data Privacy Regulation Compliance in 2025 Frameworks appeared first on Cyber Security News.
CISO Advisory
华为余承东:有些车卖爆了但产品不太好,尊界 S800 百万顶配超七成
10 months ago
贴上「界」标,就能躺赢......了吗?
CVE-2005-4385 | Cofax 1.9.9c/1.9.9d/2.0 Rc1/2.0 Rc2/2.0 Rc3 search.htm searchstring cross site scripting (EDB-26879 / BID-15940)
10 months ago
A vulnerability was found in Cofax 1.9.9c/1.9.9d/2.0 Rc1/2.0 Rc2/2.0 Rc3 and classified as problematic. Affected by this issue is some unknown functionality of the file search.htm. The manipulation of the argument searchstring leads to basic cross site scripting.
This vulnerability is handled as CVE-2005-4385. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-4863 | GetSimple CMS 2.01 post-title cross site scripting (EDB-34789 / XFDB-62177)
10 months ago
A vulnerability, which was classified as problematic, was found in GetSimple CMS 2.01. Affected is an unknown function. The manipulation of the argument post-title leads to cross site scripting.
This vulnerability is traded as CVE-2010-4863. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2005-1440 | Codetosell ViArt Shop Enterprise 2.1.6 basket.php category_id cross site scripting (EDB-25575 / BID-13462)
10 months ago
A vulnerability has been found in Codetosell ViArt Shop Enterprise 2.1.6 and classified as problematic. This vulnerability affects unknown code of the file basket.php. The manipulation of the argument category_id leads to basic cross site scripting.
This vulnerability was named CVE-2005-1440. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2002-0681 | Goahead Webserver 2.1.1/2.1.2/2.1.3/2.1.4/2.1.5 404 Error Message cross site scripting (EDB-21608 / ID 86369)
10 months ago
A vulnerability, which was classified as problematic, has been found in Goahead Webserver 2.1.1/2.1.2/2.1.3/2.1.4/2.1.5. This issue affects some unknown processing of the component 404 Error Message. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2002-0681. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2011-0276 | HP OpenView Performance Insight 5.31 doPost memory corruption (EDB-16984 / Nessus ID 51850)
10 months ago
A vulnerability classified as very critical was found in HP OpenView Performance Insight 5.31. Affected by this vulnerability is the function doPost of the component HP OpenView. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2011-0276. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
D^3CTF 2025
10 months ago
Name: D^3CTF 2025 (an D^3CTF event.)
Date: May 30, 2025, noon — 31 May 2025, 12:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://d3c.tf/
Rating weight: 54.67
Event organizers: D^3CTF Organizers
Date: May 30, 2025, noon — 31 May 2025, 12:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://d3c.tf/
Rating weight: 54.67
Event organizers: D^3CTF Organizers
CVE-2000-0653 | Microsoft Outlook Express 5.5 Persistent Browser Link information disclosure (MS00-045 / EDB-19738)
10 months ago
A vulnerability was found in Microsoft Outlook Express 5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Persistent Browser Link Handler. The manipulation leads to information disclosure.
This vulnerability was named CVE-2000-0653. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-0400 | IBM WebSphere eXtreme Scale up to 7.1.0.2/7.1.1.0/8.5.0.2/8.6.0.7 crlf injection (EDB-40039)
10 months ago
A vulnerability classified as critical was found in IBM WebSphere eXtreme Scale up to 7.1.0.2/7.1.1.0/8.5.0.2/8.6.0.7. Affected by this vulnerability is an unknown functionality. The manipulation leads to crlf injection.
This vulnerability is known as CVE-2016-0400. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2000-0567 | Microsoft Outlook up to 2000 Date Field memory corruption (EDB-20078 / XFDB-4953)
10 months ago
A vulnerability was found in Microsoft Outlook up to 2000 and classified as critical. This issue affects some unknown processing of the component Date Field Handler. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2000-0567. The attack may be initiated remotely. Furthermore, there is an exploit available. Due to its background and reception, this vulnerability has an historic impact.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-3219 | Microsoft Windows 10 Kernel win32k.sys access control (MS16-074 / EDB-39993)
10 months ago
A vulnerability was found in Microsoft Windows 10. It has been declared as critical. This vulnerability affects unknown code in the library win32k.sys of the component Kernel. The manipulation leads to improper access controls.
This vulnerability was named CVE-2016-3219. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com