Aggregator
CVE-2024-11858 | radare2 up to 5.9.8 on 64-bit Pebble Application File command injection
1 year 5 months ago
A vulnerability was found in radare2 up to 5.9.8 on 64-bit and classified as critical. This issue affects some unknown processing of the component Pebble Application File Handler. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2024-11858. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-36464 | Zabbix up to 6.0.29/6.4.15/7.0.0 Media Type Export credentials storage
1 year 5 months ago
A vulnerability has been found in Zabbix up to 6.0.29/6.4.15/7.0.0 and classified as problematic. This vulnerability affects unknown code of the component Media Type Export. The manipulation leads to unprotected storage of credentials.
This vulnerability was named CVE-2024-36464. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Право на защиту: банки раскроют клиентам личности дроперов
1 year 5 months ago
Госдума обсуждает инициативы против мошенников.
CVE-2024-8114:GitLab 漏洞允许权限升级
1 year 5 months ago
安全客
CVE-2024-42333 | Zabbix up to 6.0.33/6.4.18/7.0.3 email.c buffer over-read
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Zabbix up to 6.0.33/6.4.18/7.0.3. This affects an unknown part in the library src/libs/zbxmedia/email.c. The manipulation leads to buffer over-read.
This vulnerability is uniquely identified as CVE-2024-42333. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42326 | Zabbix up to 7.0.3 browser.c es_browser_get_variant use after free
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Zabbix up to 7.0.3. Affected by this issue is the function es_browser_get_variant of the file browser.c. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-42326. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36468 | Zabbix up to 7.0.2rc1 Proxy zbx_snmp_cache_handle_engineid stack-based overflow
1 year 5 months ago
A vulnerability classified as problematic was found in Zabbix up to 7.0.2rc1. Affected by this vulnerability is the function zbx_snmp_cache_handle_engineid of the component Proxy. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-36468. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42332 | Zabbix up to 6.0.33/6.4.18/7.0.3 SNMP Trap Log Parser injection
1 year 5 months ago
A vulnerability classified as problematic has been found in Zabbix up to 6.0.33/6.4.18/7.0.3. Affected is an unknown function of the component SNMP Trap Log Parser. The manipulation leads to injection.
This vulnerability is traded as CVE-2024-42332. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42331 | Zabbix up to 7.0.3 Duktape JavaScript Engine browser.c es_browser_ctor use after free
1 year 5 months ago
A vulnerability was found in Zabbix up to 7.0.3. It has been rated as problematic. This issue affects the function es_browser_ctor in the library src/libs/zbxembed/browser.c of the component Duktape JavaScript Engine. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-42331. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42330 | Zabbix up to 6.0.33/6.4.18/7.0.3 HttpRequest format string
1 year 5 months ago
A vulnerability was found in Zabbix up to 6.0.33/6.4.18/7.0.3. It has been declared as critical. This vulnerability affects unknown code of the component HttpRequest Handler. The manipulation leads to format string.
This vulnerability was named CVE-2024-42330. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42329 | Zabbix up to 7.0.3rc1 webdriver_session_query unchecked return value to null pointer dereference
1 year 5 months ago
A vulnerability was found in Zabbix up to 7.0.3rc1. It has been classified as problematic. This affects the function webdriver_session_query. The manipulation leads to unchecked return value to null pointer dereference.
This vulnerability is uniquely identified as CVE-2024-42329. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42328 | Zabbix up to 7.0.2 curl_write_cb unchecked return value to null pointer dereference
1 year 5 months ago
A vulnerability was found in Zabbix up to 7.0.2 and classified as problematic. Affected by this issue is the function curl_write_cb. The manipulation leads to unchecked return value to null pointer dereference.
This vulnerability is handled as CVE-2024-42328. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42327 | Zabbix up to 6.0.31/6.4.16/7.0.1 API addRelatedObjects sql injection
1 year 5 months ago
A vulnerability has been found in Zabbix up to 6.0.31/6.4.16/7.0.1 and classified as critical. Affected by this vulnerability is the function addRelatedObjects of the component API. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-42327. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53635 | PHPGurukul COVID 19 Testing Management System 1.0 POST Request Parameter patient-search-report.php searchdata cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in PHPGurukul COVID 19 Testing Management System 1.0. Affected is an unknown function of the file /covid-tms/patient-search-report.php of the component POST Request Parameter Handler. The manipulation of the argument searchdata leads to cross site scripting.
This vulnerability is traded as CVE-2024-53635. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-53604 | PHPGurukul COVID 19 Testing Management System 1.0 POST Request Parameter check_availability.php mobnumber sql injection
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID 19 Testing Management System 1.0. This issue affects some unknown processing of the file /covid-tms/check_availability.php of the component POST Request Parameter Handler. The manipulation of the argument mobnumber leads to sql injection.
The identification of this vulnerability is CVE-2024-53604. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-53603 | PHPGurukul COVID 19 Testing Management System 1.0 POST Request Parameter password-recovery.php contactno sql injection
1 year 5 months ago
A vulnerability classified as critical was found in PHPGurukul COVID 19 Testing Management System 1.0. This vulnerability affects unknown code of the file /covid-tms/password-recovery.php of the component POST Request Parameter Handler. The manipulation of the argument contactno leads to sql injection.
This vulnerability was named CVE-2024-53603. The attack can be initiated remotely. There is no exploit available.
vuldb.com
威胁行为者 RomCom 利用 Mozilla Firefox 和 Microsoft Windows 中的零日漏洞发起协同攻击
1 year 5 months ago
安全客
Police bust pirate streaming service making €250 million per month
1 year 5 months ago
An international law enforcement operation has dismantled a pirate streaming service that served over 22 million users worldwide and made €250 million ($263M) per month. [...]
Bill Toulas
DICOMHawk:用于检测和记录未经授权访问尝试的蜜罐系统
1 year 5 months ago
DICOMHawk是一款功能强大且高效的 DICOM 服务器蜜罐,可以帮助广大研究人员检测和记录未经授权的访问尝试。