Aggregator
SpaceX星舰第六次试飞成功,特朗普现场观看;余承东首秀华为Mate 70 Pro+真机;索尼收购老头环开发商|极客早知道
1 year 6 months ago
英伟达与谷歌量子 AI 部门达成合作;
苹果中国 App Store 每周访客量达 1.5 亿;
小红书:开展史上最严黑灰产账号治理行动;
小鹏汽车第三季度营收 101.0 亿元人民币
CVE-2024-25941 | FreeBSD jail information disclosure
1 year 6 months ago
A vulnerability classified as problematic was found in FreeBSD. Affected by this vulnerability is an unknown functionality of the component jail. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-25941. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52374 | Huawei HarmonyOS/EMUI access control
1 year 6 months ago
A vulnerability classified as problematic has been found in Huawei HarmonyOS and EMUI. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2023-52374. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2023-52558 | OpenBSD up to 7.3/7.4 Network Buffer buffer size
1 year 6 months ago
A vulnerability was found in OpenBSD up to 7.3/7.4. It has been rated as critical. This issue affects some unknown processing of the component Network Buffer Handler. The manipulation leads to incorrect calculation of buffer size.
The identification of this vulnerability is CVE-2023-52558. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28745 | AbemaTV ABEMA App prior 10.65.0 on Android access control
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in AbemaTV ABEMA App on Android. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-28745. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-28013 | NEC WG1800HP4 Setting random values
1 year 6 months ago
A vulnerability, which was classified as problematic, was found in NEC WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN. This affects an unknown part of the component Setting Handler. The manipulation leads to insufficiently random values.
This vulnerability is uniquely identified as CVE-2024-28013. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-52348 | Unisoc S8000 Ril Service out-of-bounds write
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in Unisoc SC7731E, SC9832E, SC9863A, T310, T606, T612, T616, T610, T618, T760, T770, T820 and S8000. This issue affects some unknown processing of the component Ril Service. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2023-52348. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2024-31813 | Totolink EX200 4.0.3c.7646_B20201211 missing authentication
1 year 6 months ago
A vulnerability was found in Totolink EX200 4.0.3c.7646_B20201211. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to missing authentication.
The identification of this vulnerability is CVE-2024-31813. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-21058 | Oracle Database Enterprise Edition up to 19.22/21.13 Audit Component improper authorization
1 year 6 months ago
A vulnerability was found in Oracle Database Enterprise Edition up to 19.22/21.13. It has been classified as critical. Affected is an unknown function of the component Audit Component. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2024-21058. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52728 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 putBitString array index (Issue 245)
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25. Affected by this issue is the function putBitString. The manipulation leads to improper validation of array index.
This vulnerability is handled as CVE-2023-52728. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-45922 | Freedesktop Mesa 23.0.4 __glXGetDrawableAttribute null pointer dereference (Nessus ID 208211)
1 year 6 months ago
A vulnerability has been found in Freedesktop Mesa 23.0.4 and classified as problematic. This vulnerability affects the function __glXGetDrawableAttribute. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2023-45922. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
更新 | 适配天蝎的修正版 SoapWebShell
1 year 6 months ago
.NET 内网攻防实战电子报刊
1 year 6 months ago
.NET 反混淆神器 de4dot 的可视化版本工具
1 year 6 months ago
Daily Dose of Dark Web Informer - November 19th, 2024
1 year 6 months ago
This daily article is intended to make it easier for those who want to stay updated with my regular posts. Any subscriber-only content will be clearly marked at the end of the link.
Dark Web Informer
Similarities Between SOX And SEC's Cyber Rule - Padraic O'Reilly - BSW #373
1 year 6 months ago
Nov 19, 2024The Sarbanes-Oxley (SOX) Act was a watershed moment in corporategovernance, fundamental
Trader Loses $26M in ezETH Tokens: Media Blames User, Hacker Calls Out ERC-20 Flaws
1 year 6 months ago
My name is Dexaran. I’m a hacker, I’ve designed and executed one of the largest consensus-level at
The HackerNoon Newsletter: Is AI Progress Slowing? The Scaling Debate OpenAI Doesn’t Want to Have (11/19/2024)
1 year 6 months ago
17家单位联发《工业和信息化领域数据安全合规指引》
1 year 6 months ago
11月19日,17家单位联合发布《工业和信息化领域数据安全合规指引》,聚焦数据处理者在履行数据安全保护义务过程中的难点问题,明确数据安全合规依据,提供实务指引,有利于支撑数据处理者全面、准确、规范开展数据安全合规管理,提升数据安全保护能力。
关注本公众号【威努特安全网络】,在对话框回复【合规指引】获取原文。
编制单位:
工业信息安全产业发展联盟
中国钢铁工业协会
中国有色金属工业协会
中国石油和化学工业联合会
中国建筑材料联合会
中国机械工业联合会
中国汽车工业协会
中国纺织工业联合会
中国轻工业联合会
中国电子信息行业联合会
中国计算机行业协会
中国通信企业协会
中国互联网协会
中国通信标准化协会
中国中小企业国际合作协会
中国通信学会
工业和信息化部商用密码应用产业促进联盟