Aggregator
CVE-2014-3444 | RealNetworks RealPlayer 16.0.0/16.0.0.282/16.0.1.18/16.0.2.32/16.0.3.51 3GP File code injection (File 126637 / EDB-39182)
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in RealNetworks RealPlayer 16.0.0/16.0.0.282/16.0.1.18/16.0.2.32/16.0.3.51. Affected by this issue is some unknown functionality of the component 3GP File Handler. The manipulation leads to code injection.
This vulnerability is handled as CVE-2014-3444. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-7382 | VICIDIAL 2.7/2.8 credentials management (EDB-29513)
9 months 1 week ago
A vulnerability has been found in VICIDIAL 2.7/2.8 and classified as critical. This vulnerability affects unknown code. The manipulation leads to credentials management.
This vulnerability was named CVE-2013-7382. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-1137 | Charles Steinkuehler sh-httpd 0.3/0.4 GET Request privileges management (EDB-23295 / XFDB-13519)
9 months 1 week ago
A vulnerability, which was classified as critical, was found in Charles Steinkuehler sh-httpd 0.3/0.4. Affected is an unknown function of the component GET Request Handler. The manipulation with the input * leads to improper privilege management.
This vulnerability is traded as CVE-2003-1137. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2011-5140 | DiY-CMS blog 1.0 tags.php start sql injection (EDB-18288 / XFDB-72022)
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in DiY-CMS blog 1.0. Affected by this issue is some unknown functionality of the file tags.php. The manipulation of the argument start leads to sql injection.
This vulnerability is handled as CVE-2011-5140. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
地缘信息知识星球近期情报成品报告一览
9 months 1 week ago
地缘信息知识星球近期情报成品报告一览
如何围绕一个人开展全方位的情报搜集
9 months 1 week ago
如何围绕一个人开展全方位的情报搜集
CVE-2007-0885 | Rainbow with the Zen cross site scripting (EDB-29576 / XFDB-32418)
9 months 1 week ago
A vulnerability was found in Rainbow with the Zen. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2007-0885. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
统一化的eBPF学习环境搭建,附代码
9 months 1 week ago
统一化的eBPF学习环境搭建,附代码
中国公司仍然不太愿意采用本国替代芯片
9 months 1 week ago
尽管本国芯片在部分领域取得了突破,但中国公司仍然不太愿意采用本国替代芯片。原因包括芯片工艺制程的落后,产量低、国外竞争对手的产品可用性和可靠性已经过了验证,以及缺乏政府的强制性要求。以 AI 和 HPC 为例,美国限制中国公司采购英伟达的 H100 或 H200 芯片,而本土 AI 芯片缺乏软件生态,在性能上甚至无法与英伟达的弱化版本 HGX H20 竞争。中国企业担心失去竞争力,宁愿选择弱化版本或通过走私等方法采购。在汽车芯片市场,国内公司规模小产量低,难以挑战国外的老牌产品。中国公司对外国芯片的依赖在可预见的未来仍将会持续下去。
CVE-1999-0736 | Microsoft IIS 4.0 showcode.asp privileges management (MS99-013 / EDB-19129)
9 months 1 week ago
A vulnerability, which was classified as critical, was found in Microsoft IIS 4.0. This affects an unknown part of the file showcode.asp. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-1999-0736. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2004-0110 | XMLSoft libxml2 up to 2.6.5 nanohttp/nanoftp memory corruption (EDB-601 / Nessus ID 14118)
9 months 1 week ago
A vulnerability classified as critical has been found in XMLSoft libxml2 up to 2.6.5. This affects an unknown part of the component nanohttp/nanoftp. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2004-0110. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
威胁情报周报(12.2~12.8)
9 months 1 week ago
一周情报速览~
CVE-2011-5200 | DeDeCMS 5.6 list.php id sql injection (EDB-18292 / XFDB-72034)
9 months 1 week ago
A vulnerability classified as critical was found in DeDeCMS 5.6. Affected by this vulnerability is an unknown functionality of the file list.php. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2011-5200. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2005-2250 | Nokia Affix up to 3.2.0 FTP Client memory corruption (EDB-1081 / Nessus ID 19225)
9 months 1 week ago
A vulnerability classified as critical has been found in Nokia Affix up to 3.2.0. Affected is an unknown function of the component FTP Client. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2005-2250. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-2449 | Apache Tomcat up to 5.5.1 cross site scripting (EDB-30189 / Nessus ID 67536)
9 months 1 week ago
A vulnerability was found in Apache Tomcat up to 5.5.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting.
This vulnerability is handled as CVE-2007-2449. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
因云层减少地球在 2023 年吸收了更多的阳光
9 months 1 week ago
由于云层覆盖的面积减少,德国科学家报告地球在 2023 年吸收了更多的阳光。低空云层的覆盖面积平均每十年减少约 1.3%,而 2023 年减少的幅度比往年略大。是什么导致云层消失?科学家提出了三种可能的解释:气候系统的正常变动,意味着 2023 年是异常的一年,未来几年情况会恢复;由于对污染的控制气溶胶减少了,气溶胶能播种云去反射阳光;气温上升对低空云层的影响——这一解释最令人担忧,意味着全球暖化会加剧,由于气温上升,云层变得稀疏,导致地球吸收了更多的热量,地球进一步暖化,这意味着高温的趋势会持续下去。
CVE-2000-0493 | Atrius Trivalie Simple Network Time Sync 1.0 String memory corruption (EDB-19978 / XFDB-4602)
9 months 1 week ago
A vulnerability, which was classified as very critical, has been found in Atrius Trivalie Simple Network Time Sync 1.0. This issue affects some unknown processing of the component String Handler. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2000-0493. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-8871 | libcroco 0.6.12 CSS File cr-parser.c cr_parser_parse_selector_core resource management (EDB-42147 / ID 172445)
9 months 1 week ago
A vulnerability classified as problematic was found in libcroco 0.6.12. This vulnerability affects the function cr_parser_parse_selector_core of the file cr-parser.c of the component CSS File Handler. The manipulation leads to improper resource management.
This vulnerability was named CVE-2017-8871. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-1999-0278 | Microsoft IIS 3.0/4.0 ASP File URL information disclosure (MS98-003 / EDB-19118)
9 months 1 week ago
A vulnerability classified as critical was found in Microsoft IIS 3.0/4.0. This vulnerability affects unknown code of the component ASP File Handler. The manipulation with the input ::$DATA as part of URL leads to information disclosure.
This vulnerability was named CVE-1999-0278. The attack can be initiated remotely. Furthermore, there is an exploit available. This vulnerability has a historic impact due to its background and reception.
It is recommended to apply a patch to fix this issue.
vuldb.com