Aggregator
黑哥2023年内部培训视频合集
9 months 2 weeks ago
黑哥2023年内部培训视频合集
9 months 2 weeks ago
CVE-2016-4595 | Apple Mac OS X up to 10.11.5 Safari Login AutoFill information disclosure (HT206903 / Nessus ID 92496)
9 months 2 weeks ago
A vulnerability classified as critical has been found in Apple Mac OS X up to 10.11.5. Affected is an unknown function of the component Safari Login AutoFill. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2016-4595. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-3604 | Seyeon FlexWATCH Network Camera up to 3.0 Access Restriction path traversal (EDB-28208 / XFDB-27656)
9 months 2 weeks ago
A vulnerability classified as critical was found in Seyeon FlexWATCH Network Camera up to 3.0. This vulnerability affects unknown code of the component Access Restriction. The manipulation leads to path traversal.
This vulnerability was named CVE-2006-3604. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Password management habits you should unlearn
9 months 2 weeks ago
Despite advancements in security technology, many individuals and organizations continue to rely on outdated and vulnerable authentication methods, leaving themselves exposed to cyber threats. This ongoing reliance on insecure methods has led to a steady rise in fraud, with weak password practices and password reuse contributing to a thriving market for stolen credentials. In this article, find out more about the most prevalent authentication practices, their associated risks, and the necessity of implementing stronger security … More →
The post Password management habits you should unlearn appeared first on Help Net Security.
Help Net Security
CVE-2007-4585 | 2532gigs 1.2.1 activateuser.php language path traversal (EDB-4317 / XFDB-36267)
9 months 2 weeks ago
A vulnerability was found in 2532gigs 1.2.1. It has been rated as critical. This issue affects some unknown processing of the file activateuser.php. The manipulation of the argument language leads to path traversal.
The identification of this vulnerability is CVE-2007-4585. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Medusa Blog
9 months 2 weeks ago
cohenido
CVE-2019-0344 | SAP Commerce Cloud up to 1905 virtualjdbc extension code injection
9 months 2 weeks ago
A vulnerability was found in SAP Commerce Cloud up to 1905 and classified as critical. Affected by this issue is some unknown functionality of the component virtualjdbc extension. The manipulation leads to code injection.
This vulnerability is handled as CVE-2019-0344. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-4043 | GPAC up to 1.0.x null pointer dereference
9 months 2 weeks ago
A vulnerability classified as problematic has been found in GPAC up to 1.0.x. Affected is an unknown function. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2021-4043. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7593 | Ivanti vTM up to 22.2R0/22.7R1 improper authentication
9 months 2 weeks ago
A vulnerability was found in Ivanti vTM up to 22.2R0/22.7R1 and classified as very critical. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2024-7593. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
New Threat Actor
9 months 2 weeks ago
cohenido
CVE-2024-9029 | Freeimage tiff_read_iptc_profile heap-based overflow
9 months 2 weeks ago
A vulnerability was found in Freeimage. It has been declared as critical. This vulnerability affects the function tiff_read_iptc_profile. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-9029. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-6654 | ESET Cyber Security/Endpoint Security on macOS temp file
9 months 2 weeks ago
A vulnerability classified as problematic was found in ESET Cyber Security and Endpoint Security on macOS. This vulnerability affects unknown code. The manipulation leads to insecure temporary file.
This vulnerability was named CVE-2024-6654. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38861 | Checkmk Exchange Plugin up to 2.0a/2.5.5 certificate validation
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Checkmk Exchange Plugin up to 2.0a/2.5.5. This issue affects some unknown processing. The manipulation leads to improper certificate validation.
The identification of this vulnerability is CVE-2024-38861. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-39431 | Unisoc S8000 UMTS RLC Driver out-of-bounds write
9 months 2 weeks ago
A vulnerability was found in Unisoc SC7731E, SC9832E, SC9863A, T310, T606, T612, T616, T610, T618, T760, T770, T820 and S8000 and classified as critical. Affected by this issue is some unknown functionality of the component UMTS RLC Driver. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2024-39431. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-39432 | Unisoc S8000 UMTS RLC Driver out-of-bounds
9 months 2 weeks ago
A vulnerability was found in Unisoc SC7731E, SC9832E, SC9863A, T310, T606, T612, T616, T610, T618, T760, T770, T820 and S8000. It has been classified as critical. This affects an unknown part of the component UMTS RLC Driver. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2024-39432. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-39434 | Unisoc T606/T612/T616/T610/T618/T760/T770/T820/S8000 Drm Service out-of-bounds
9 months 2 weeks ago
A vulnerability was found in Unisoc T606, T612, T616, T610, T618, T760, T770, T820 and S8000. It has been declared as critical. This vulnerability affects unknown code of the component Drm Service. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-39434. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2024-39433 | Unisoc T606/T612/T616/T610/T618/T760/T770/T820/S8000 Drm Service out-of-bounds write
9 months 2 weeks ago
A vulnerability was found in Unisoc T606, T612, T616, T610, T618, T760, T770, T820 and S8000. It has been rated as critical. This issue affects some unknown processing of the component Drm Service. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2024-39433. The attack needs to be approached locally. There is no exploit available.
vuldb.com
Nitrogen
9 months 2 weeks ago
cohenido