Aggregator
特朗普新政府对美国国防政策与战略影响分析
8 months 3 weeks ago
特朗普、马斯克与泽连斯基通话细节大公开
8 months 3 weeks ago
Critical Remote Code Execution Vulnerability in Palo Alto Networks PAN
8 months 3 weeks ago
On November 8, 2024, Palo Alto Networks issued a security advisory concerning a potential remote code execution (RCE) vulnerability affecting […]
The post Critical Remote Code Execution Vulnerability in Palo Alto Networks PAN appeared first on HawkEye.
HawkEye
r2con 2024 将在油管同步直播
8 months 3 weeks ago
radare2 是一款命令行下的反汇编工具,并提供官方支持的 GUI 项目 iaito。感觉用户群不如另外几家商业产品庞大,不过有竞品对用户来说总是好事。
r2con 是面向 radare2 社区的会议,今年也有一些关于 frida 和移动安全的议题。比如非越狱环境下 frida 在真机和模拟器上的配置,简单的应用加固,分别针对流行框架 Flutter 和 Unity 的逆向案例等。
完整议程在此:
https://rada.re/con/2024/
昨天是 workshop 环节,会棍博主就直接跳过了。来之前还有些紧张。上周瓦伦西亚发生的洪灾让人心有余悸,前几天巴塞罗那也遭遇了暴雨袭击。还好这周末看起来很平静。
主会议日程在巴塞罗那当地时间 9 点开始,对应北京时间下午 16 点。有兴趣的可以挑议题观看免费直播。目前地址还没放出来,到时可以看这个油管频道:
https://www.youtube.com/@r2con/streams
啃生肉有困难?Chrome 浏览器现在已经内置了实时翻译中文字幕的功能,右上角点两下即可开启。
CVE-2024-51785 | I Thirteen Web Solution Responsive Filterable Portfolio Plugin up to 1.0.22 on WordPress server-side request forgery
8 months 3 weeks ago
A vulnerability classified as critical has been found in I Thirteen Web Solution Responsive Filterable Portfolio Plugin up to 1.0.22 on WordPress. This affects an unknown part. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-51785. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
双十一开放注册微信抽奖活动,再送40个账号注册码或300论坛币,明天下午两点开奖,详见:【开放注册公告】吾爱破解论坛2024年11月11日光棍节开放注册公告。 PS:上次参加完活动的同学这次参加需要重新分享上传。
8 months 3 weeks ago
CVE-2019-10086 | Oracle JD Edwards EnterpriseOne Tools up to 9.2.5.2 Portal SEC deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability classified as critical was found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.5.2. Affected by this vulnerability is an unknown functionality of the component Portal SEC. The manipulation leads to deserialization.
This vulnerability is known as CVE-2019-10086. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle PeopleSoft Enterprise PT PeopleTools 8.56/8.57/8.58 Weblogic deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability was found in Oracle PeopleSoft Enterprise PT PeopleTools 8.56/8.57/8.58. It has been classified as critical. Affected is an unknown function of the component Weblogic. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2019-10086. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle Retail Advanced Inventory Planning 14.1 Operations / Maintenance deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability was found in Oracle Retail Advanced Inventory Planning 14.1 and classified as critical. This issue affects some unknown processing of the component Operations / Maintenance. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2019-10086. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle Retail Back Office 14.1 Pricing deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability was found in Oracle Retail Back Office 14.1. It has been classified as critical. Affected is an unknown function of the component Pricing. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2019-10086. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle Service Bus 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Web Container deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability was found in Oracle Service Bus 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0. It has been declared as critical. This vulnerability affects unknown code of the component Web Container. The manipulation leads to deserialization.
This vulnerability was named CVE-2019-10086. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle WebLogic Server 10.3.6.0.0 Core deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability was found in Oracle WebLogic Server 10.3.6.0.0. It has been rated as critical. This issue affects some unknown processing of the component Core. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2019-10086. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle Healthcare Foundation 7.1.5/7.2.2/7.3.0/7.3.1/8.0.1 Self Service Analytics deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability was found in Oracle Healthcare Foundation 7.1.5/7.2.2/7.3.0/7.3.1/8.0.1. It has been rated as critical. This issue affects some unknown processing of the component Self Service Analytics. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2019-10086. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle Hospitality OPERA 5 5.5/5.6 Integrations deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability has been found in Oracle Hospitality OPERA 5 5.5/5.6 and classified as critical. This vulnerability affects unknown code of the component Integrations. The manipulation leads to deserialization.
This vulnerability was named CVE-2019-10086. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle Insurance Data Gateway 1.0.2.3 Apache Commons BeanUtils deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability classified as critical has been found in Oracle Insurance Data Gateway 1.0.2.3. This affects an unknown part of the component Apache Commons BeanUtils. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2019-10086. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.5.2 E1 IOT Orchestrator Security deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability classified as critical has been found in Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.5.2. Affected is an unknown function of the component E1 IOT Orchestrator Security. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2019-10086. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-10086 | Oracle Fusion Middleware 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 Centralized Thirdparty Jars deserialization (Nessus ID 210560)
8 months 3 weeks ago
A vulnerability was found in Oracle Fusion Middleware 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 and classified as critical. Affected by this issue is some unknown functionality of the component Centralized Thirdparty Jars. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2019-10086. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11048 | D-Link DI-8003 16.07.16A1 /dbsrv.asp dbsrv_asp str stack-based overflow
8 months 3 weeks ago
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been rated as critical. Affected by this issue is the function dbsrv_asp of the file /dbsrv.asp. The manipulation of the argument str leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2024-11048. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-11047 | D-Link DI-8003 16.07.16A1 /upgrade_filter.asp upgrade_filter_asp path stack-based overflow
8 months 3 weeks ago
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected by this vulnerability is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-11047. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com