Aggregator
Pwn 2Own柏林回顾:VMware收件箱、Windows 11遭零日黑客攻击
10 months 1 week ago
安全客
帕洛阿尔托网络公司警告XSS漏洞,并使用SEARCH漏洞代码
10 months 1 week ago
安全客
Нет приложения — нет Москвы: мигрантам придётся жить по координатам GPS
10 months 1 week ago
Отпечатки, селфи, адрес, слежка — с 1 сентября это обязательный чек-лист для въезда в столицу.
硬核守护!360解密两大高危勒索软件,助力用户夺回“数据主权”获致谢。
10 months 1 week ago
安全客
Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs
10 months 1 week ago
A Google Chrome Web Store campaign uses over 100 malicious browser extensions that mimic legitimate tools, such as VPNs, AI assistants, and crypto utilities, to steal browser cookies and execute remote scripts secretly. [...]
Bill Toulas
‘Deep concern’ for domestic abuse survivors as cybercriminals expected to publish confidential refuge addresses
10 months 1 week ago
A data extortion incident impacting the British government’s Legal Aid Agency could have serious implications for vulnerable people.
Alleged Sale of Shell Access to an Unidentified Company in Germany
10 months 1 week ago
Alleged Sale of Shell Access to an Unidentified Company in Germany
Dark Web Informer - Cyber Threat Intelligence
Flaw in Google Cloud Functions Sparks Broader Security Concerns
10 months 1 week ago
Patched privilege escalation flaw in Google Cloud Platform linked to wider cloud security concerns
BSidesLV24 – GroundFloor – Insert Coin: Hacking Arcades For Fun
10 months 1 week ago
Authors/Presenters: Ignacio Navarro
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – GroundFloor – Insert Coin: Hacking Arcades For Fun appeared first on Security Boulevard.
Marc Handelman
CVE-2020-8622 | ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1 TSIG Response assertion (Nessus ID 236577)
10 months 1 week ago
A vulnerability classified as problematic has been found in ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1. This affects an unknown part of the component TSIG Handler. The manipulation as part of Response leads to reachable assertion.
This vulnerability is uniquely identified as CVE-2020-8622. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-8623 | ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1 PKCS11 denial of service (Nessus ID 236577)
10 months 1 week ago
A vulnerability classified as problematic was found in ISC BIND up to 9.11.21/9.16.5/9.17.3/9.1.21-S1. This vulnerability affects unknown code of the component PKCS11 Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2020-8623. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-8622 | Oracle Communications Diameter Signaling Router up to 8.5.0.0 BIND denial of service (Nessus ID 236577)
10 months 1 week ago
A vulnerability was found in Oracle Communications Diameter Signaling Router up to 8.5.0.0. It has been declared as critical. This vulnerability affects unknown code of the component BIND. The manipulation leads to denial of service.
This vulnerability was named CVE-2020-8622. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13313 | libosinfo 1.5.0 osinfo-install-script Credentials credentials management (RHSA-2019:3387 / Nessus ID 236578)
10 months 1 week ago
A vulnerability was found in libosinfo 1.5.0 and classified as problematic. Affected by this issue is some unknown functionality of the component osinfo-install-script. The manipulation leads to credentials management (Credentials).
This vulnerability is handled as CVE-2019-13313. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2019-6465 | ISC BIND Zone Transfer permission assignment (RHSA-2019:3552 / Nessus ID 236577)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in ISC BIND up to 9.10.8-P1/9.11.5-P2/9.11.5-S3/9.12.3-P2/9.13.6. This issue affects some unknown processing of the component Zone Transfer Handler. The manipulation leads to incorrect permission assignment.
The identification of this vulnerability is CVE-2019-6465. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-6471 | ISC BIND up to 9.15.0 dispatch.c Malformed Packet race condition (K10092301 / Nessus ID 236577)
10 months 1 week ago
A vulnerability was found in ISC BIND up to 9.15.0. It has been classified as problematic. This affects an unknown part of the file dispatch.c. The manipulation as part of Malformed Packet leads to race condition.
This vulnerability is uniquely identified as CVE-2019-6471. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2020-8617 | ISC BIND up to 9.17.1 TSIG tsig.c Message assertion (EDB-48521 / Nessus ID 236577)
10 months 1 week ago
A vulnerability classified as problematic was found in ISC BIND up to 9.17.1. This vulnerability affects unknown code of the file tsig.c of the component TSIG Handler. The manipulation as part of Message leads to reachable assertion.
This vulnerability was named CVE-2020-8617. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-3570 | linuxptp up to 3.1.0 ptp4l memory corruption (Nessus ID 236579)
10 months 1 week ago
A vulnerability has been found in linuxptp up to 3.1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ptp4l. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2021-3570. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-3677 | PostgreSQL up to 11.12/12.7/13.3 Query information disclosure (Nessus ID 236581 / Replaces VDB-182163)
10 months 1 week ago
A vulnerability was found in PostgreSQL up to 11.12/12.7/13.3. It has been classified as problematic. This affects an unknown part of the component Query Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2021-3677. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-23214 | PostgreSQL up to 14.0 sql injection (Nessus ID 236581)
10 months 1 week ago
A vulnerability, which was classified as critical, was found in PostgreSQL up to 14.0. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2021-23214. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com