Aggregator
【安全圈】ChatGPT 客户端曝“记忆”漏洞,黑客可令 AI “转发对话记录”
9 months 1 week ago
【安全圈】寻求刺激入侵视频监控系统,一男子被山东警方采取刑事强制措施
9 months 1 week ago
A cyberattack on Kuwait Health Ministry impacted hospitals in the country
9 months 1 week ago
The Kuwait Health Ministry is recovering from a cyberattack that disrupted systems at multiple hospitals and disabled the Sahel healthcare app. Kuwait’s Health Ministry was the victim of a cyberattack that took systems at several of the country’s hospitals offline. The cyber attack also impacted the Ministry of Health website, which is still offline, and […]
Pierluigi Paganini
CVE-2024-38559 | Linux Kernel up to 6.9.2 qedf memdup_user_nul buffer overflow (Nessus ID 207773)
9 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.9.2. It has been classified as critical. This affects the function memdup_user_nul of the component qedf. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-38559. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38579 | Linux Kernel up to 6.9.2 crypto spu2_dump_omd buffer overflow (Nessus ID 207773)
9 months 1 week ago
A vulnerability has been found in Linux Kernel up to 6.9.2 and classified as critical. Affected by this vulnerability is the function spu2_dump_omd of the component crypto. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2024-38579. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47412 | Linux Kernel up to 5.14.10 block rq_qos_done_bio denial of service (004b8f8a6912/a647a524a467 / Nessus ID 207773)
9 months 1 week ago
A vulnerability classified as critical was found in Linux Kernel up to 5.14.10. This vulnerability affects the function rq_qos_done_bio of the component block. The manipulation leads to denial of service.
This vulnerability was named CVE-2021-47412. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36901 | Linux Kernel up to 6.1.90/6.6.30/6.8.9 ip6_output null pointer dereference (Nessus ID 207773)
9 months 1 week ago
A vulnerability has been found in Linux Kernel up to 6.1.90/6.6.30/6.8.9 and classified as critical. Affected by this vulnerability is the function ip6_output. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-36901. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42152 | Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8 nvmet_sq_destroy allocation of resources (Nessus ID 207773)
9 months 1 week ago
A vulnerability has been found in Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8 and classified as problematic. This vulnerability affects the function nvmet_sq_destroy. The manipulation leads to allocation of resources.
This vulnerability was named CVE-2024-42152. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43830 | Linux Kernel up to 6.1.102/6.6.43/6.10.2 trigger deactivate allocation of resources (Nessus ID 207773)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.1.102/6.6.43/6.10.2. Affected is the function deactivate of the component trigger. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-43830. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26638 | Linux Kernel up to 6.1.75/6.6.14/6.7/6.7.2 nbd uninitialized pointer (Nessus ID 207773)
9 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.1.75/6.6.14/6.7/6.7.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component nbd. The manipulation leads to uninitialized pointer.
This vulnerability is known as CVE-2024-26638. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36919 | Linux Kernel up to 6.8.9 bnx2fc mm/vmalloc.c Privilege Escalation (Nessus ID 207773)
9 months 1 week ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.8.9. Affected by this vulnerability is an unknown functionality of the file mm/vmalloc.c of the component bnx2fc. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-36919. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36922 | Linux Kernel up to 6.6.30/6.8.9 iwlwifi memory corruption (b83db8e756de/43d07103df67/c2ace6300600 / Nessus ID 207773)
9 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.6.30/6.8.9 and classified as critical. This issue affects some unknown processing of the component iwlwifi. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2024-36922. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47101 | Linux Kernel up to 5.15.11 asix_common.c asix_mdio_read uninitialized pointer (d259f621c859/8035b1a2a37a / Nessus ID 207773)
9 months 1 week ago
A vulnerability was found in Linux Kernel up to 5.15.11 and classified as problematic. Affected by this issue is the function asix_mdio_read of the file drivers/net/usb/asix_common.c. The manipulation leads to uninitialized pointer.
This vulnerability is handled as CVE-2021-47101. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26939 | Linux Kernel up to 6.1.87/6.6.28/6.8.2/6.9-rc1 i915 lib/debugobjects.c __active_retire use after free (Nessus ID 207773)
9 months 1 week ago
A vulnerability has been found in Linux Kernel up to 6.1.87/6.6.28/6.8.2/6.9-rc1 and classified as critical. Affected by this vulnerability is the function __active_retire in the library lib/debugobjects.c of the component i915. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-26939. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
U.S. Charges Three Iranian Nationals for Election Interference and Cybercrimes
9 months 1 week ago
U.S. federal prosecutors on Friday unsealed criminal charges against three Iranian nationals who are allegedly employed with the Islamic Revolutionary Guard Corps (IRGC) for their targeting of current and former officials to steal sensitive data.
The Department of Justice (DoJ) accused Masoud Jalili, 36, Seyyed Ali Aghamiri, 34, and Yasar (Yaser) Balaghi, 37, of participating in a conspiracy
The Hacker News
CVE-2024-40998 | Linux Kernel up to 6.6.35/6.9.6 __ext4_fill_super initialization (23afcd52af06/645267906944/b4b4fda34e53 / Nessus ID 207773)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.35/6.9.6. This affects the function __ext4_fill_super. The manipulation leads to improper initialization.
This vulnerability is uniquely identified as CVE-2024-40998. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40972 | Linux Kernel up to 6.9.6 ext4 ext4_xattr_set_entry allocation of resources (111103907234/0a46ef234756 / Nessus ID 207773)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.9.6. Affected is the function ext4_xattr_set_entry of the component ext4. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-40972. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41055 | Linux Kernel up to 5.10.221/5.15.162/6.1.99/6.6.40/6.9.9 pfn_section_valid null pointer dereference (Nessus ID 207773)
9 months 1 week ago
A vulnerability classified as critical was found in Linux Kernel up to 5.10.221/5.15.162/6.1.99/6.6.40/6.9.9. This vulnerability affects the function pfn_section_valid. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-41055. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26595 | Linux Kernel up to 6.6.13/6.7.1 mlxsw mlxsw_sp_acl_tcam_region_destroy null pointer dereference (817840d125a3/d0a1efe417c9/efeb7dfea8ee / Nessus ID 207773)
9 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.6.13/6.7.1. It has been rated as critical. This issue affects the function mlxsw_sp_acl_tcam_region_destroy of the component mlxsw. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-26595. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com