Aggregator
来了,Frida源码情景分析
1 year 5 months ago
The Return of Mystique? Possibly the most valuable userspace Android vulnerability in recent years: CVE-2024-31317
1 year 5 months ago
flanker017
7 петаватт в точке с волос: в Колорадо строят революционный лазерный комплекс
1 year 5 months ago
Цель — изменить подход к термоядерной энергетике и лечению опухолей.
CVE-2024-43689 | ELECOM WAB-I1750-PS/WAB-S1167-PS up to 1.5.10 HTTP Request stack-based overflow
1 year 5 months ago
A vulnerability was found in ELECOM WAB-I1750-PS and WAB-S1167-PS up to 1.5.10 and classified as critical. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2024-43689. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8625 | TS Poll Plugin up to 2.3.x on WordPress sql injection
1 year 5 months ago
A vulnerability has been found in TS Poll Plugin up to 2.3.x on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-8625. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10202 | Wellchoose Administrative Management System os command injection
1 year 5 months ago
A vulnerability, which was classified as critical, was found in Wellchoose Administrative Management System. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-10202. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10200 | Wellchoose Administrative Management System path traversal
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Wellchoose Administrative Management System. This issue affects some unknown processing. The manipulation leads to relative path traversal.
The identification of this vulnerability is CVE-2024-10200. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-49215 | Sangoma Asterisk/Certified Asterisk manager.c action_getconfig/action_getconfigJson path traversal
1 year 5 months ago
A vulnerability classified as critical has been found in Sangoma Asterisk and Certified Asterisk. This affects the function action_getconfig/action_getconfigJson of the file manager.c. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-49215. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-10201 | Wellchoose Administrative Management System unrestricted upload
1 year 5 months ago
A vulnerability classified as critical was found in Wellchoose Administrative Management System. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-10201. The attack can be initiated remotely. There is no exploit available.
vuldb.com
字节跳动以恶意干扰 AI 模型训练为由解雇了一名实习生
1 year 5 months ago
TikTok 母公司字节跳动证实以恶意干扰 AI 模型训练为由解雇了一名实习生,但否认该实习生破坏了数千张卡造成了数千万元的损失。字节跳动的豆包 AI 聊天机器人是中国最受欢迎的 AI 聊天机器人之一。字节跳动在声明中称,涉事实习生恶意干扰商业化技术团队研究项目的模型训练任务,但并不影响商业化的正式项目及线上业务,也不涉及字节跳动大模型等其他业务。涉事人一直在商业化技术团队实习,并没有 AI Lab 实习经历。该实习生已在 8 月被公司辞退。公司也将其行为同步给行业联盟和所在学校,交由校方处理。
CVE-2016-1082 | Adobe Acrobat Reader up to 11.0.15/15.006 memory corruption (APSB16-14 / Nessus ID 91096)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Adobe Acrobat Reader up to 11.0.15/15.006. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2016-1082. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers
1 year 5 months ago
Cybersecurity researchers have discovered severe cryptographic issues in various end-to-end encrypted (E2EE) cloud storage platforms that could be exploited to leak sensitive data.
"The vulnerabilities range in severity: in many cases a malicious server can inject files, tamper with file data, and even gain direct access to plaintext," ETH Zurich researchers Jonas Hofmann and Kien Tuong Truong
The Hacker News
CVE-2005-4195 | Scout Portal Toolkit SPT--UserLogin.php sql injection (EDB-5540 / XFDB-23547)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in Scout Portal Toolkit. This affects an unknown part of the file SPT--UserLogin.php. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2005-4195. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.
vuldb.com
CVE-2005-4195 | Internet Scout Project Scout Portal Toolkit up to 1.3.1 spt--browseresources.php ResourceOffset sql injection (EDB-5540 / XFDB-42169)
1 year 5 months ago
A vulnerability was found in Internet Scout Project Scout Portal Toolkit up to 1.3.1. It has been classified as critical. Affected is an unknown function of the file spt--browseresources.php. The manipulation of the argument ResourceOffset leads to sql injection.
This vulnerability is traded as CVE-2005-4195. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2181 | cpLinks 1.03 Error Message search.php cross site scripting (EDB-5538 / XFDB-42171)
1 year 5 months ago
A vulnerability was found in cpLinks 1.03 and classified as problematic. This issue affects some unknown processing of the file search.php of the component Error Message Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2008-2181. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2193 | ScorpNews 2.0 example.php site code injection (EDB-5539 / XFDB-42517)
1 year 5 months ago
A vulnerability classified as critical has been found in ScorpNews 2.0. Affected is an unknown function of the file example.php. The manipulation of the argument site leads to code injection.
This vulnerability is traded as CVE-2008-2193. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2180 | cpLinks 1.03 admin_username sql injection (EDB-5538 / XFDB-42170)
1 year 5 months ago
A vulnerability has been found in cpLinks 1.03 and classified as critical. This vulnerability affects unknown code. The manipulation of the argument admin_username leads to sql injection.
This vulnerability was named CVE-2008-2180. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Цифровой мираж – стратегия Microsoft по шпионажу за хакерами
1 year 5 months ago
Как фейковые компании помогают в поимке злоумышленников.
CVE-2001-0928 | GNOME libgtop Daemon up to 1.0.13 Authentication permitted memory corruption (VU#705771 / Nessus ID 15138)
1 year 5 months ago
A vulnerability was found in GNOME libgtop Daemon up to 1.0.13. It has been declared as critical. Affected by this vulnerability is the function permitted of the component Authentication. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2001-0928. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com