Aggregator
【安全圈】耗时2个月,四川小伙用专业知识把自己“送进去”了。
1 year 7 months ago
Weekly Update 426
1 year 7 months ago
I have absolutely no problem at all talking about the code I've screw
CVE-2021-31215 | SchedMD Slurm up to 20.02.6/20.11.6 Script Privilege Escalation (Nessus ID 211087)
1 year 7 months ago
A vulnerability has been found in SchedMD Slurm up to 20.02.6/20.11.6 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Script Handler. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2021-31215. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42010 | D-Bus up to 1.12.23/1.14.3/1.15.1 libdbus denial of service (Issue 418 / Nessus ID 211086)
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in D-Bus up to 1.12.23/1.14.3/1.15.1. This affects an unknown part of the component libdbus. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2022-42010. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42011 | D-Bus up to 1.12.23/1.14.3/1.15.1 Array Length denial of service (Issue 413 / Nessus ID 211086)
1 year 7 months ago
A vulnerability has been found in D-Bus up to 1.12.23/1.14.3/1.15.1 and classified as problematic. This vulnerability affects unknown code of the component Array Length Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2022-42011. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42012 | D-Bus up to 1.12.23/1.14.3/1.15.1 libdbus denial of service (Issue 417 / Nessus ID 211086)
1 year 7 months ago
A vulnerability was found in D-Bus up to 1.12.23/1.14.3/1.15.1 and classified as problematic. This issue affects some unknown processing of the component libdbus. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2022-42012. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-43337 | SchedMD Slurm up to 20.11.7 access control (Nessus ID 211087)
1 year 7 months ago
A vulnerability was found in SchedMD Slurm and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2021-43337. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-41742 | Nginx Open Source/Open Source Subscription/Plus ngx_http_mp4_module out-of-bounds write (K28112382 / Nessus ID 211091)
1 year 7 months ago
A vulnerability was found in Nginx Open Source, Open Source Subscription and Plus. It has been classified as critical. This affects an unknown part of the component ngx_http_mp4_module. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2022-41742. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-41741 | Nginx Open Source/Open Source Subscription/Plus ngx_http_mp4_module out-of-bounds write (K81926432 / Nessus ID 211091)
1 year 7 months ago
A vulnerability was found in Nginx Open Source, Open Source Subscription and Plus and classified as critical. This issue affects some unknown processing of the component ngx_http_mp4_module. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2022-41741. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DataCon2024 | 第五个比赛日,各战队火力全开
1 year 7 months ago
最新排名公布
Black Suit
1 year 7 months ago
cohenido
大模型褪去野蛮生长后,百度的新思考
1 year 7 months ago
降温之后,该如何穿越周期?
Akira
1 year 7 months ago
cohenido
[指南] 苹果承认iCloud备忘录在同意协议后消失并发布解决方案
1 year 7 months ago
JSP3/2.0.14
「会说话」的 AI ,扣子智能语音 OpenAPI 开启内测申请
1 year 7 months ago
给客服打电话总是遇到让人高血压的 AI ?智能音箱对话时总是被错误识别?AI 陪伴机器人总是感觉有点呆板?语音交互体验似乎成为了 AI 落地的一块绊脚石。试试扣子智能语音 OpenAPI ,将有望使这
为什么没有真正的零信任?
1 year 7 months ago
“零信任”是一种思维方式的转变,它不是解决所有问题,我们永远不会到达那里,大多数安全技术都与零信任相称或支持零信任。如果这为接近安全提供了北极星或一般思维方式,那就是它的价值所在。你永远不会到达完整的
苹果向多个市场的用户退还以旧换新AppleCare+服务费 但原因尚不清楚
1 year 7 months ago
JSP3/2.0.14
AI Homework Helper Ai作业辅导
1 year 7 months ago
简介:
AI Homework Helper 是一款在线AI工具,帮助学生快速解决作业难题。用户可以上传图片或PDF格式的作业,AI会自动生成准确的解答及详细的步骤说明,涵盖数学、科学等多个学科...
黑海洋
Week in review: Microsoft patches actively exploited 0-days, Amazon and HSBC employee data leaked
1 year 7 months ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039) November 2024 Patch Tuesday is here, and Microsoft has dropped fixes for 89 new security issues in its various products, two of which – CVE-2024-43451 and CVE-2024-49039 – are actively exploited by attackers. Massive troves of Amazon, HSBC employee data leaked A threat actor who goes by the online moniker “Nam3L3ss” has leaked … More →
The post Week in review: Microsoft patches actively exploited 0-days, Amazon and HSBC employee data leaked appeared first on Help Net Security.
Help Net Security