Aggregator
CVE-2024-20143 | MediaTek MT8676 V6 DA out-of-bounds write (MSV-2069 / ALPS09167056)
1 year 5 months ago
A vulnerability was found in MediaTek MT2737, MT6781, MT6789, MT6835, MT6855, MT6878, MT6879, MT6880, MT6886, MT6890, MT6895, MT6897, MT6980, MT6983, MT6985, MT6989, MT6990, MT8370, MT8390 and MT8676. It has been declared as problematic. This vulnerability affects unknown code of the component V6 DA. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-20143. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20152 | MediaTek MT8893 WLAN STA driver assertion (MSV-1798 / ALPS09136505)
1 year 5 months ago
A vulnerability was found in MediaTek MT2737, MT3603, MT6835, MT6878, MT6886, MT6897, MT6990, MT7902, MT7920, MT7922, MT8518S, MT8532, MT8755, MT8766, MT8768, MT8775, MT8781, MT8796, MT8798 and MT8893. It has been classified as problematic. This affects an unknown part of the component WLAN STA driver. The manipulation leads to reachable assertion.
This vulnerability is uniquely identified as CVE-2024-20152. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20140 | MediaTek MT8532 Power out-of-bounds write (MSV-2020 / ALPS09270402)
1 year 5 months ago
A vulnerability was found in MediaTek MT6739, MT6761, MT6768, MT6781, MT6833, MT6853, MT6877, MT6885, MT6893, MT8518S and MT8532 and classified as critical. Affected by this issue is some unknown functionality of the component Power. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2024-20140. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20105 | MediaTek MT8768 m4u out-of-bounds write (MSV-1743 / ALPS09062027)
1 year 5 months ago
A vulnerability has been found in MediaTek MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6889, MT6893, MT6895, MT6983, MT8666, MT8667, MT8673 and MT8768 and classified as critical. Affected by this vulnerability is an unknown functionality of the component m4u. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2024-20105. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20151 | MediaTek MT8863 Modem out-of-bounds write (MSV-1928 / MOLY01399339)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in MediaTek MT2737, MT2739, MT6789, MT6813, MT6815, MT6835, MT6835T, MT6855, MT6878, MT6878T, MT6879, MT6886, MT6895, MT6895T, MT6896, MT6897, MT6899, MT6980, MT6980D, MT6983, MT6985, MT6986, MT6986D, MT6988, MT6989, MT6990, MT6991, MT8676, MT8678, MT8798 and MT8863. Affected is an unknown function of the component Modem. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2024-20151. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-12302 | Icegram Engage Plugin up to 3.1.31 on WordPress Campaign Setting cross site scripting
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Icegram Engage Plugin up to 3.1.31 on WordPress. This issue affects some unknown processing of the component Campaign Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-12302. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20146 | MediaTek MT8893 WLAN STA driver out-of-bounds write (MSV-1835 / ALPS09137491)
1 year 5 months ago
A vulnerability classified as critical was found in MediaTek MT2737, MT3603, MT6835, MT6878, MT6886, MT6897, MT6990, MT7902, MT7920, MT7922, MT8365, MT8518S, MT8532, MT8666, MT8667, MT8673, MT8755, MT8766, MT8768, MT8775, MT8781, MT8786, MT8788, MT8796, MT8798 and MT8893. This vulnerability affects unknown code of the component WLAN STA driver. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-20146. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
纽约时报科技专栏将优秀科技奖颁给微软工程师Andres Freund表彰其发现XZ后门
1 year 5 months ago
#科技资讯 纽约时报科技专栏将年度优秀科技奖颁发给微软数据库工程师 Andres Freund 表彰其发现了 XZ 项目的后门,从而挫败一场可能威胁数亿台计算机的破坏行动。XZ 项目在
Garak – An Open Source LLM Vulnerability Scanner for AI Red-Teaming
1 year 5 months ago
Garak is a free, open-source tool specifically designed to test the robustness and reliability of Large Language Models (LLMs). Inspired by utilities like Nmap or Metasploit, Garak identifies potential weak points in LLMs by probing for issues such as hallucinations, data leakage, prompt injections, toxicity, jailbreak effectiveness, and misinformation propagation. This guide covers everything you […]
The post Garak – An Open Source LLM Vulnerability Scanner for AI Red-Teaming appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Balaji
CVE-2024-11849 | Pods Plugin up to 3.2.8.0 on WordPress Setting cross site scripting
1 year 5 months ago
A vulnerability classified as problematic has been found in Pods Plugin up to 3.2.8.0 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11849. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11356 | tourmaster Plugin up to 5.3.3 on WordPress cross site scripting
1 year 5 months ago
A vulnerability was found in tourmaster Plugin up to 5.3.3 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11356. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20150 | MediaTek MT8863 Modem deserialization (MSV-2018 / MOLY01412526)
1 year 5 months ago
A vulnerability was found in MediaTek MT2735, MT2737, MT6767, MT6768, MT6769, MT6769K, MT6769S, MT6769T, MT6769Z, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6878, MT6878M, MT6879, MT6880, MT6880T, MT6880U, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6899, MT6980, MT6980D, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT6991, MT8666, MT8673, MT8675, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8789, MT8791T, MT8795T, MT8797, MT8798 and MT8863. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Modem. The manipulation leads to deserialization.
This vulnerability is known as CVE-2024-20150. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20149 | MediaTek MT8863 Modem improper validation of specified quantity in input (MSV-2165 / MOLY01231341)
1 year 5 months ago
A vulnerability was found in MediaTek MT2735, MT2737, MT6767, MT6768, MT6769, MT6769K, MT6769S, MT6769T, MT6769Z, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6878, MT6878M, MT6879, MT6880, MT6880T, MT6880U, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6899, MT6980, MT6980D, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT6991, MT8666, MT8673, MT8675, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8789, MT8791T, MT8795T, MT8797, MT8798 and MT8863. It has been classified as critical. Affected is an unknown function of the component Modem. The manipulation leads to improper validation of specified quantity in input.
This vulnerability is traded as CVE-2024-20149. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20154 | MediaTek MT8798 Modem stack-based overflow (MSV-2392 / MOLY00720348)
1 year 5 months ago
A vulnerability was found in MediaTek MT2735, MT6767, MT6768, MT6769, MT6769K, MT6769S, MT6769T, MT6769Z, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6833P, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6880, MT6880T, MT6880U, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT8666, MT8673, MT8675, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8789, MT8791T, MT8795T, MT8797 and MT8798 and classified as critical. This issue affects some unknown processing of the component Modem. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-20154. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20153 | MediaTek MT8893 WLAN STA missing critical step in authentication (MSV-1598 / ALPS08990446)
1 year 5 months ago
A vulnerability has been found in MediaTek MT2737, MT6989, MT6991, MT7925, MT8365, MT8518S, MT8532, MT8666, MT8667, MT8673, MT8676, MT8678, MT8755, MT8766, MT8768, MT8775, MT8781, MT8786, MT8788, MT8796, MT8798 and MT8893 and classified as problematic. This vulnerability affects unknown code of the component WLAN STA. The manipulation leads to missing critical step in authentication.
This vulnerability was named CVE-2024-20153. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20148 | MediaTek MT8798 WLAN STA FW out-of-bounds write (MSV-1796 / ALPS09136494)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in MediaTek MT3603, MT6835, MT6878, MT6886, MT6897, MT7902, MT7920, MT7922, MT8518S, MT8532, MT8766, MT8768, MT8775, MT8796 and MT8798. This affects an unknown part of the component WLAN STA FW. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-20148. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
The TechBeat: Programmable Bitcoin Is Here: A Turing-complete Bridgeless Bitcoin Execution Layer (1/6/2025)
1 year 5 months ago
Make Malware Happy, (Mon, Jan 6th)
1 year 5 months ago
When I teach FOR610[1], I like to use a funny quotation with my students: “Make malware happy!” Wha
雷神众测漏洞周报2024.12.30-2025.1.5
1 year 5 months ago
雷神众测拥有该文章的修改和解释权。如欲转载或传播此文章,必须保证此文章的副本,包括版权声明等全部内容。声明雷神众测允许,不得任意修改或增减此文章内容,不得以任何方式将其用于商业目的。