Aggregator
Play
10 months 2 weeks ago
cohenido
CVE-2001-0167 | AT&T WinVNC 3.3.3r7 rfbConnFailed Packet Reason memory corruption (EDB-16489 / ID 38022)
10 months 2 weeks ago
A vulnerability classified as very critical has been found in AT&T WinVNC 3.3.3r7. This affects an unknown part of the component rfbConnFailed Packet Handler. The manipulation of the argument Reason leads to memory corruption.
This vulnerability is uniquely identified as CVE-2001-0167. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-7129 | ISS BlackICE PC Protection 3.6 api (EDB-28817 / XFDB-29575)
10 months 2 weeks ago
A vulnerability was found in ISS BlackICE PC Protection 3.6. It has been rated as problematic. Affected by this issue is the function api. The manipulation leads to an unknown weakness.
This vulnerability is handled as CVE-2006-7129. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
CVE-2016-3373 | Microsoft Windows up to Vista Kernel API Registry access control (MS16-111 / EDB-40430)
10 months 2 weeks ago
A vulnerability classified as problematic has been found in Microsoft Windows up to Vista. Affected is an unknown function of the component Kernel API. The manipulation leads to improper access controls (Registry).
This vulnerability is traded as CVE-2016-3373. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
AI Domination: RSAC 2025 Social Media Roundup
10 months 2 weeks ago
Documented in a series of social media posts, cybersecurity experts shared with Dark Reading their insights on RSAC 2025 throughout the week.
Kristina Beek, Associate Editor, Dark Reading
'Venom Spider' Targets Hiring Managers in Phishing Scheme
10 months 2 weeks ago
Researchers from Arctic Wolf Labs detailed a new spear-phishing campaign that targets hiring managers and recruiters by posing as a job seeker.
Alexander Culafi, Senior News Writer, Dark Reading
NHI Solutions That Fit Your Budget
10 months 2 weeks ago
Why Opt for Budget-Friendly NHIs? Ever wondered how budget-friendly Non-Human Identities (NHIs) can redefine your organization’s cybersecurity? Through the strategic management of NHIs and their secrets, businesses can establish robust security controls, decrease the risk of breaches, and promote company-wide compliance – all while staying within budget. Cybersecurity Redefined: Harnessing the Power of NHIs NHIs […]
The post NHI Solutions That Fit Your Budget appeared first on Entro.
The post NHI Solutions That Fit Your Budget appeared first on Security Boulevard.
Alison Mack
CVE-2018-18938 | WUZHI CMS 4.1.0 index.php?m=core&f=index Attribute Stored cross site scripting (Issue 158)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in WUZHI CMS 4.1.0. Affected by this issue is some unknown functionality of the file index.php?m=core&f=index. The manipulation as part of Attribute leads to cross site scripting (Stored).
This vulnerability is handled as CVE-2018-18938. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2019-9107 | WUZHI CMS 4.1.0 cross site scripting (ID 169)
10 months 2 weeks ago
A vulnerability has been found in WUZHI CMS 4.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS]. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2019-9107. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2019-9109 | WUZHI CMS 4.1.0 cross site scripting (ID 172)
10 months 2 weeks ago
A vulnerability was found in WUZHI CMS 4.1.0. It has been classified as problematic. This affects an unknown part of the file index.php?m=message&f=message&v=add&username=[XSS]. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2019-9109. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2019-9110 | WUZHI CMS 4.1.0 cross site scripting (ID 170)
10 months 2 weeks ago
A vulnerability was found in WUZHI CMS 4.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2019-9110. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2018-17425 | WUZHI CMS 4.1.0 Membership Center index.php?m=member Stored cross site scripting (Issue 153)
10 months 2 weeks ago
A vulnerability classified as problematic has been found in WUZHI CMS 4.1.0. Affected is an unknown function of the file index.php?m=member of the component Membership Center. The manipulation leads to cross site scripting (Stored).
This vulnerability is traded as CVE-2018-17425. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2018-17426 | WUZHI CMS 4.1.0 Extension Module index.php?m=core Stored cross site scripting (Issue 154)
10 months 2 weeks ago
A vulnerability classified as problematic was found in WUZHI CMS 4.1.0. Affected by this vulnerability is an unknown functionality of the file index.php?m=core of the component Extension Module. The manipulation leads to cross site scripting (Stored).
This vulnerability is known as CVE-2018-17426. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2019-8062 | Adobe After Effects up to 16 Library Loader untrusted search path (APSB19-31)
10 months 2 weeks ago
A vulnerability has been found in Adobe After Effects up to 16 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Library Loader. The manipulation leads to untrusted search path.
This vulnerability is known as CVE-2019-8062. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2020-10827 | DrayTek Vigor3900/Vigor2960/Vigor300B up to 1.5.0 HTTP Request out-of-bounds write
10 months 2 weeks ago
A vulnerability was found in DrayTek Vigor3900, Vigor2960 and Vigor300B up to 1.5.0. It has been classified as critical. Affected is an unknown function. The manipulation as part of HTTP Request leads to out-of-bounds write.
This vulnerability is traded as CVE-2020-10827. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-10828 | DrayTek Vigor3900/Vigor2960/Vigor300B up to 1.5.0 HTTP Request out-of-bounds write
10 months 2 weeks ago
A vulnerability was found in DrayTek Vigor3900, Vigor2960 and Vigor300B up to 1.5.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation as part of HTTP Request leads to out-of-bounds write.
This vulnerability is known as CVE-2020-10828. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-11868 | ntp up to 4.2.8p13/4.3.99 ntpd Source IP Address denial of service (DLA 2201-1)
10 months 2 weeks ago
A vulnerability was found in ntp up to 4.2.8p13/4.3.99. It has been declared as problematic. This vulnerability affects unknown code of the component ntpd. The manipulation as part of Source IP Address leads to denial of service.
This vulnerability was named CVE-2020-11868. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
New "Bring Your Own Installer" EDR bypass used in ransomware attack
10 months 2 weeks ago
A new "Bring Your Own Installer" EDR bypass technique is exploited in attacks to bypass SentinelOne's tamper protection feature, allowing threat actors to disable endpoint detection and response (EDR) agents to install the Babuk ransomware. [...]
Lawrence Abrams
Canary Exploit Tool for CVE-2025-30065 Apache Parquet Avro Vulnerability
10 months 2 weeks ago
Investigating a schema parsing concern in the parquet-avro module of Apache Parquet Java.