Aggregator
PwnSec CTF 2024
1 year 5 months ago
Name: PwnSec CTF 2024 (an PwnSec CTF event.)
Date: Nov. 15, 2024, 3 p.m. — 16 Nov. 2024, 15:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.pwnsec.xyz/
Rating weight: 23.92
Event organizers: PwnSec
Date: Nov. 15, 2024, 3 p.m. — 16 Nov. 2024, 15:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.pwnsec.xyz/
Rating weight: 23.92
Event organizers: PwnSec
互联网档案馆提供《虚幻》和《虚幻竞技场》的免费下载
1 year 5 months ago
互联网档案馆(Internet Archive)获得游戏发行商 Epic Games 的许可提供《虚幻(1998)》和《虚幻竞技场》的免费下载。玩家可以直接从互联网档案馆下载游戏,从 Github 上下载补丁以兼容当前版本的 Windows,或者通过 oldunreal.com 提供的安装程序。两款游戏虽然年代久远,但都能在目前的硬件上运行,用户可能需要调整默认设置,如 640x480 分辨率和反向鼠标控制。
CVE-2022-1507 | chafa up to 1.10.1 libnsgif.c gif_internal_decode_frame null pointer dereference (Nessus ID 211215)
1 year 5 months ago
A vulnerability has been found in chafa up to 1.10.1 and classified as problematic. Affected by this vulnerability is the function gif_internal_decode_frame of the file libnsgif.c. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2022-1507. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-35015 | Advancecomp 2.3 /lib/endianrw.h le_uint32_read heap-based overflow (Nessus ID 211214)
1 year 5 months ago
A vulnerability was found in Advancecomp 2.3. It has been rated as critical. This issue affects the function le_uint32_read in the library /lib/endianrw.h. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2022-35015. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2022-35016 | Advancecomp 2.3 heap-based overflow (Nessus ID 211214)
1 year 5 months ago
A vulnerability classified as critical has been found in Advancecomp 2.3. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2022-35016. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2022-35014 | Advancecomp 2.3 memory corruption (Nessus ID 211214)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Advancecomp 2.3. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2022-35014. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2020-14394 | QEMU USB xHCI Controller Emulation hw/usb/hcd-xhci.c xhci_ring_chain_length denial of service (Nessus ID 211221)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in QEMU. Affected by this issue is the function xhci_ring_chain_length of the file hw/usb/hcd-xhci.c of the component USB xHCI Controller Emulation. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2020-14394. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2022-21626 | Oracle Java SE 8u341/8u345-perf/11.0.16.1 Security denial of service (Nessus ID 211218)
1 year 5 months ago
A vulnerability was found in Oracle Java SE 8u341/8u345-perf/11.0.16.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Security. The manipulation leads to denial of service.
This vulnerability is known as CVE-2022-21626. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-3775 | grub2 Font Code out-of-bounds write (Nessus ID 211216)
1 year 5 months ago
A vulnerability was found in grub2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Font Code. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2022-3775. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-2601 | grub2 grub_font_construct_glyph max_glyph_size out-of-bounds write (Nessus ID 211216)
1 year 5 months ago
A vulnerability was found in grub2. It has been declared as critical. This vulnerability affects the function grub_font_construct_glyph. The manipulation of the argument max_glyph_size leads to out-of-bounds write.
This vulnerability was named CVE-2022-2601. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-8637 | Google Chrome up to 128.0.6613.119 Media Router use after free (Nessus ID 211222)
1 year 5 months ago
A vulnerability classified as critical has been found in Google Chrome. This affects an unknown part of the component Media Router. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-8637. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8638 | Google Chrome up to 128.0.6613.119 V8 type confusion (Nessus ID 211222)
1 year 5 months ago
A vulnerability classified as critical was found in Google Chrome. This vulnerability affects unknown code of the component V8. The manipulation leads to type confusion.
This vulnerability was named CVE-2024-8638. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8639 | Google Chrome up to 128.0.6613.119 Autofill use after free (Nessus ID 211222)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Google Chrome. This issue affects some unknown processing of the component Autofill. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-8639. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8636 | Google Chrome up to 128.0.6613.119 Skia heap-based overflow (Nessus ID 211222)
1 year 5 months ago
A vulnerability was found in Google Chrome. It has been rated as critical. Affected by this issue is some unknown functionality of the component Skia. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-8636. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0226 | Apple MacOS X up to 10.10.2 Apache race condition (HT204659 / EDB-34133)
1 year 5 months ago
A vulnerability was found in Apple MacOS X up to 10.10.2. It has been classified as critical. Affected is an unknown function of the component Apache. The manipulation leads to race condition.
This vulnerability is traded as CVE-2014-0226. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
微重力下的精子活性显著下降
1 year 5 months ago
实验显示,微重力环境可能对精子健康构成不小的挑战。研究团队从 15 位男性身上收集了精子样本,将每个样本一分为二:一半留在地球,另一半则送上进行抛物线飞行的飞机,模拟微重力环境进行实验。结果发现,处于微重力条件下的精子样本,其运动能力(活力)与存活率显著下降,虽然微重力环境不会直接杀死精子,但精子的健康状况明显受到影响。精子的曲线速度(VCL,又称轨迹速度,是精子头部沿实际行走曲线的运动速度)受到的影响尤为显著,这代表在太空中,成功受精的机率可能大幅下降。此外,精子的活力与存活率的下降可能会随着微重力暴露时间的延长而加剧。不过,并非所有的影响都是负面的,微重力环境对于精子的 DNA 完整性、形态、氧化压力以及计划性细胞凋亡没有明显影响,这些结果为未来探索太空中的辅助生殖技术提供了一定的希望。
全世界的糖尿病患者人数超过了 8 亿
1 year 5 months ago
《柳叶刀》刊发的一篇论文称,2022 年全球罹患Ⅰ型或Ⅱ型糖尿病的成年人总数已超 8 亿,是 1990 年的 4 倍多。研究人员从各国收集了 1000 多项研究,涵盖 1.4 亿 18 岁以上人群的数据,利用统计工具,估算出了不同国家糖尿病的发病率和治疗情况。数据显示,从 1990 年到 2022 年,全球男性和女性的糖尿病发病率都翻了一番:男性从 6.8% 增至 14.3%;女性从 6.9% 增至 13.9%。由于人口增长和老龄化的影响,2022 年估计有 8.28 亿成年人患有糖尿病,比 1990 年增加了约 6.3 亿人。其中超过四分之一(2.12亿)糖尿病患者生活在印度,中国约 1.48 亿。绝大多数成年人罹患的是Ⅱ型糖尿病。肥胖和不良饮食是Ⅱ型糖尿病发病率上升,及其在各国之间造成差异的重要驱动因素。
CVE-2024-9849 | FlipBook, PDF Viewer, PDF Embedder Plugin up to 4.6 on WordPress unrestricted upload
1 year 5 months ago
A vulnerability was found in FlipBook, PDF Viewer, PDF Embedder Plugin up to 4.6 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-9849. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9839 | Uix Slideshow Plugin up to 1.6.5 on WordPress Shortcode code injection
1 year 5 months ago
A vulnerability was found in Uix Slideshow Plugin up to 1.6.5 on WordPress. It has been classified as critical. Affected is an unknown function of the component Shortcode Handler. The manipulation leads to code injection.
This vulnerability is traded as CVE-2024-9839. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com