Aggregator
CVE-2019-19143 | TP-LINK TL-WR849N 0.9.1 Firmware cgi/softup POST Request improper authentication (ID 156586 / EDB-48152)
1 year 6 months ago
A vulnerability, which was classified as very critical, was found in TP-LINK TL-WR849N 0.9.1. This affects an unknown part of the file cgi/softup of the component Firmware Handler. The manipulation as part of POST Request leads to improper authentication.
This vulnerability is uniquely identified as CVE-2019-19143. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Congress Seeks Urgent Action After Chinese Telecom Hack
1 year 6 months ago
Lawmakers Demand Answers, Security Overhaul After Chinese Hack of Telecom Networks
Congress is demanding answers from AT&T, Verizon, and Lumen after reports revealed that Chinese hackers breached U.S. telecom infrastructure, targeting systems linked to court-authorized wiretaps, as the FBI and the Cybersecurity and Infrastructure Security Agency investigate the Salt Typhoon group.
Congress is demanding answers from AT&T, Verizon, and Lumen after reports revealed that Chinese hackers breached U.S. telecom infrastructure, targeting systems linked to court-authorized wiretaps, as the FBI and the Cybersecurity and Infrastructure Security Agency investigate the Salt Typhoon group.
Revenue Cycle Vendor Notifying 400,000 Patients of Hack
1 year 6 months ago
Texas-Based Gryphon Healthcare Says an Unnamed Third Party Was at Center of Breach
A Texas-based revenue cycle management firm is notifying about 400,000 individuals of a hacking incident it says originated with another third party. The incident is among a growing list of major breaches implicating vendors and cumulatively affecting tens of millions of patients so far this year.
A Texas-based revenue cycle management firm is notifying about 400,000 individuals of a hacking incident it says originated with another third party. The incident is among a growing list of major breaches implicating vendors and cumulatively affecting tens of millions of patients so far this year.
Oil and Gas Firms Aware of Cyber Risks
1 year 6 months ago
Sector Uses Multifactor, Eschews Cloud, Can't Afford Cyber Insurance
The oil and gas industry has high levels of cyber awareness and low levels of cyber insurance, says a sectoral assessment from credit rating agency Moody's. The sector has experienced a clutch of high-profile attacks including a high-profile 2021 incident at Colonial Pipeline.
The oil and gas industry has high levels of cyber awareness and low levels of cyber insurance, says a sectoral assessment from credit rating agency Moody's. The sector has experienced a clutch of high-profile attacks including a high-profile 2021 incident at Colonial Pipeline.
Most EU Nations to Miss Upcoming NIS2 Deadline
1 year 6 months ago
Only Six Nations Have Incorporated NIS2 Into National Statute
Most European countries are set to miss a trading bloc deadline for implementing a key cybersecurity regulation that requires measures such as mandatory security auditing for essential services such as hospitals and banks. Just six countries have integrated the NIS2 directive into national law.
Most European countries are set to miss a trading bloc deadline for implementing a key cybersecurity regulation that requires measures such as mandatory security auditing for essential services such as hospitals and banks. Just six countries have integrated the NIS2 directive into national law.
CVE-2014-7689 | Longluntan GzoneRC - The RC Hobby Hub 0.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability classified as critical has been found in Longluntan GzoneRC - The RC Hobby Hub 0.1. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-7689. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2014-7688 | Home Improvement 0.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability was found in Home Improvement 0.1. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-7688. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
Kill
1 year 6 months ago
cohenido
CVE-2020-11978 | Apache Airflow up to 1.10.10 os command injection (EDB-49927)
1 year 6 months ago
A vulnerability was found in Apache Airflow up to 1.10.10 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2020-11978. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Serious Adversaries Circle Ivanti CSA Zero-Day Flaws
1 year 6 months ago
Suspected nation-state actors are spotted stringing together three different zero-days in the Ivanti Cloud Services Application to gain persistent access to a targeted system.
Dark Reading Staff
New FASTCash malware Linux variant helps steal money from ATMs
1 year 6 months ago
North Korean hackers are using a new Linux variant of the FASTCash malware to infect the payment switch systems of financial institutions and perform unauthorized cash withdrawals. [...]
Bill Toulas
CVE-2014-7686 | ChamberMe So. Co. Business Partnership 3.2 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability was found in ChamberMe So. Co. Business Partnership 3.2. It has been declared as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-7686. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2014-7685 | Razer Comms - Gaming Messenger 1.3.07 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability was found in Razer Comms - Gaming Messenger 1.3.07. It has been classified as critical. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7685. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
G.O.S.S.I.P 阅读推荐 2024-10-14 通过逻辑推理捉住大模型“说胡话”:一个基于蜕变测试的大模型幻觉检测方法
1 year 6 months ago
CVE-2016-1377 | Cisco Unity Connection up to 11.0 cross site scripting (CSCus21776 / ID 316012)
1 year 6 months ago
A vulnerability has been found in Cisco Unity Connection up to 11.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2016-1377. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2008-0468 | Flinx 1.3 category.php id sql injection (EDB-4985 / XFDB-39930)
1 year 6 months ago
A vulnerability classified as critical has been found in Flinx 1.3. Affected is an unknown function of the file category.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2008-0468. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0469 | Tiger Php News System up to 1.0b index.php catid sql injection (EDB-4984 / XFDB-39908)
1 year 6 months ago
A vulnerability classified as critical was found in Tiger Php News System up to 1.0b. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument catid leads to sql injection.
This vulnerability is known as CVE-2008-0469. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0492 | Persits XUpload 3.0 ActiveX Control xupload.ocx memory corruption (EDB-4987 / XFDB-39967)
1 year 6 months ago
A vulnerability classified as critical was found in Persits XUpload 3.0. Affected by this vulnerability is an unknown functionality of the file xupload.ocx of the component ActiveX Control. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2008-0492. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0551 | Sejoong Namo NamoInstaller.NamoInstall.1 up to 6 ActiveX Control namoinstaller.dll code injection (EDB-4986 / XFDB-39943)
1 year 6 months ago
A vulnerability was found in Sejoong Namo NamoInstaller.NamoInstall.1 up to 6. It has been rated as very critical. This issue affects some unknown processing in the library namoinstaller.dll of the component ActiveX Control. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2008-0551. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com