Aggregator
jeecg boot queryFieldBySql RCE漏洞分析
10 months 1 week ago
分享图片
10 months 1 week ago
【会员投票】感动吾爱2024 进入投票阶段 (2025.02.08~2025.02.13)
请速来给你喜欢的牛牛投出宝贵的一票。
👉 登录后投票:https://www.52pojie.cn/thread-2004345-1-1.html
CVE-2017-2523 | Apple macOS up to 10.12.4 Foundation memory corruption (EDB-42050 / BID-98584)
10 months 1 week ago
A vulnerability has been found in Apple macOS up to 10.12.4 and classified as critical. This vulnerability affects unknown code of the component Foundation. The manipulation leads to memory corruption.
This vulnerability was named CVE-2017-2523. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27354 | phpseclib up to 1.0.22/2.0.46/3.0.35 Prime denial of service (DLA 3749-1 / Nessus ID 215152)
10 months 1 week ago
A vulnerability was found in phpseclib up to 1.0.22/2.0.46/3.0.35. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Prime Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-27354. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52892 | phpseclib up to 1.0.21/2.0.45/3.0.32 x.509 Certificate Subject Alternative Name incorrect regex (Issue 1943 / Nessus ID 215152)
10 months 1 week ago
A vulnerability classified as problematic has been found in phpseclib up to 1.0.21/2.0.45/3.0.32. Affected is an unknown function of the component x.509 Certificate Handler. The manipulation of the argument Subject Alternative Name leads to incorrect regular expression.
This vulnerability is traded as CVE-2023-52892. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0977 | rust-openssl up to 0.10.69 ssl::select_next_proto use after free (Nessus ID 215151)
10 months 1 week ago
A vulnerability classified as critical has been found in rust-openssl up to 0.10.69. Affected is the function ssl::select_next_proto. The manipulation leads to use after free.
This vulnerability is traded as CVE-2025-0977. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-27017 | PuppetPu Puppet Agent prior 7.4.0 deserialization
10 months 1 week ago
A vulnerability, which was classified as critical, was found in PuppetPu Puppet Agent. This affects an unknown part. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2021-27017. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57278 | QingScan up to 1.8.0 URL index.html cross site scripting (Issue 41)
10 months 1 week ago
A vulnerability, which was classified as problematic, has been found in QingScan up to 1.8.0. Affected by this issue is some unknown functionality of the file /webscan/sqlmap/index.html of the component URL Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-57278. The attack may be launched remotely. There is no exploit available.
vuldb.com
日本三孩以上家庭将免学费上大学
10 months 1 week ago
为了减轻升学带来的家庭经济负担,日本政府在内阁会议上通过了对抚养 3 名及以上孩子的“多子女家庭”免除大学学费的法律修正案。取消收入限制,2025 年度起将有 41 万人新成为援助对象。援助对象为抚养有 3 名及以上孩子的家庭,且有上大学、短期大学、高等专科学校及专科学校的学生。即便是有 3 名孩子的家庭,如果第一个孩子已就业,则第二个孩子及以后的孩子将不再符合条件。获得援助的学生如果出席率低于 60% 将被停止资助。如果修得的学分数低于标准的 70%,学生将收到警告。
CVE-2024-53295 | Dell PowerProtect DD up to 7.10.1.40/7.13.1.10/8.1.0.10 insufficient granularity of access control (dsa-2025-022)
10 months 1 week ago
A vulnerability was found in Dell PowerProtect DD up to 7.10.1.40/7.13.1.10/8.1.0.10 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to insufficient granularity of access control.
This vulnerability is handled as CVE-2024-53295. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-22475 | Dell PowerProtect DD up to 7.10.1.40/7.13.1.10/8.1.0.10 a cryptographic primitive with a risky implementation (dsa-2025-022)
10 months 1 week ago
A vulnerability was found in Dell PowerProtect DD up to 7.10.1.40/7.13.1.10/8.1.0.10. It has been classified as problematic. This affects an unknown part. The manipulation leads to use of a cryptographic primitive with a risky implementation.
This vulnerability is uniquely identified as CVE-2025-22475. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1114 | newbee-mall 1.0 Add Category Page /admin/categories/save categoryName cross site scripting
10 months 1 week ago
A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category Page. The manipulation of the argument categoryName leads to cross site scripting.
This vulnerability is traded as CVE-2025-1114. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
vuldb.com
CVE-2024-48019 | Apache Doris up to 2.1.7/3.0.2 path traversal
10 months 1 week ago
A vulnerability was found in Apache Doris up to 2.1.7/3.0.2. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-48019. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0445 | Google Chrome up to 132.0.6834.159 V8 use after free (ID 392521 / Nessus ID 214952)
10 months 1 week ago
A vulnerability was found in Google Chrome. It has been rated as critical. This issue affects some unknown processing of the component V8. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2025-0445. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0444 | Google Chrome up to 132.0.6834.159 Skia use after free (ID 390889 / Nessus ID 214952)
10 months 1 week ago
A vulnerability was found in Google Chrome. It has been classified as critical. Affected is an unknown function of the component Skia. The manipulation leads to use after free.
This vulnerability is traded as CVE-2025-0444. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0451 | Google Chrome up to 132.0.6834.159 Extensions API ui layer (ID 400610 / Nessus ID 214952)
10 months 1 week ago
A vulnerability was found in Google Chrome. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Extensions API. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is known as CVE-2025-0451. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2523 | Apple iOS up to 10.3.1 Foundation memory corruption (EDB-42050 / BID-98584)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Apple iOS up to 10.3.1. This issue affects some unknown processing of the component Foundation. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2017-2523. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
调查显示:75%的员工被要求为网络安全漏洞“背锅”
10 months 1 week ago
员工对网络安全事件背锅的责任文化逐渐成为全球趋势。
波音在 Starliner 项目上总损失超过了 20 亿美元
10 months 1 week ago
波音在递交到 SEC 的 10-K 文件中披露,商业载人飞船项目 Starliner 去年花掉了 5.23 亿美元,该公司将这笔费用归因于计划延误、更高的测试和认证费用,以及更高的认证后任务费用。Starliner 去年年中将两名宇航员送去了国际空间站,原计划八天的在轨任务因飞船出现故障而变成了超过八个月的长期任务,两名宇航员至今仍然在空间站。波音公司下一次 Starliner 飞船发射变得遥遥无期。波音在该项目上的总损失超过了 20 亿美元。