Aggregator
Год под атакой: данные 1,7 млн клиентов Slim CD скомпрометированы
1 year 9 months ago
Хакеры находились в сети провайдера с августа 2023 года.
Chinese hackers linked to cybercrime syndicate arrested in Singapore
1 year 9 months ago
Six Chinese nationals and a Singaporean have been arrested on Monday in Singapore for their alleged role in malicious cyber activities committed in connection with a "global syndicate." [...]
Bill Toulas
CVE-2023-50361 | QNAP QTS/QuTS hero buffer overflow (qsa-24-20)
1 year 9 months ago
A vulnerability was found in QNAP QTS and QuTS hero. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2023-50361. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-50362 | QNAP QTS/QuTS hero buffer overflow (qsa-24-20)
1 year 9 months ago
A vulnerability classified as critical has been found in QNAP QTS and QuTS hero. This affects an unknown part. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2023-50362. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-50363 | QNAP QTS/QuTS hero authorization (qsa-24-20)
1 year 9 months ago
A vulnerability classified as critical was found in QNAP QTS and QuTS hero. This vulnerability affects unknown code. The manipulation leads to incorrect authorization.
This vulnerability was named CVE-2023-50363. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-50364 | QNAP QTS/QuTS hero buffer overflow (qsa-24-20)
1 year 9 months ago
A vulnerability, which was classified as critical, has been found in QNAP QTS and QuTS hero. This issue affects some unknown processing. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2023-50364. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39818 | Zoom Workplace App protection mechanism
1 year 9 months ago
A vulnerability classified as problematic was found in Zoom Workplace App, Workplace Desktop App, Workplace VDI Client and Meeting SDK. Affected by this vulnerability is an unknown functionality. The manipulation leads to protection mechanism failure.
This vulnerability is known as CVE-2024-39818. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-22217 | Terminalfour up to 8.3.18 server-side request forgery
1 year 9 months ago
A vulnerability has been found in Terminalfour up to 8.3.18 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2024-22217. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33508 | Fortinet FortiClientEMS up to 7.0.12/7.2.4 Requests command injection (FG-IR-24-123)
1 year 9 months ago
A vulnerability was found in Fortinet FortiClientEMS up to 7.0.12/7.2.4. It has been classified as critical. Affected is an unknown function of the component Requests Handler. The manipulation leads to command injection.
This vulnerability is traded as CVE-2024-33508. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-31489 | Fortinet FortiClientMac up to 7.0.11/7.2.4 certificate validation (FG-IR-22-282)
1 year 9 months ago
A vulnerability was found in Fortinet FortiClientMac, FortiClientEMS, FortiClientLinux and FortiClientWindows up to 7.0.11/7.2.4. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2024-31489. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-31490 | Fortinet FortiSandbox up to 3.1.5/3.2.4/4.0.5/4.2.6/4.4.4 HTTP GET Request information disclosure (FG-IR-24-051)
1 year 9 months ago
A vulnerability classified as problematic has been found in Fortinet FortiSandbox up to 3.1.5/3.2.4/4.0.5/4.2.6/4.4.4. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-31490. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27257 | IBM OpenPages 8.3/9.0 sensitive information in source
1 year 9 months ago
A vulnerability classified as problematic was found in IBM OpenPages 8.3/9.0. This vulnerability affects unknown code. The manipulation leads to inclusion of sensitive information in source code.
This vulnerability was named CVE-2024-27257. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36511 | Fortinet FortiADC up to 7.4.4 Web Application Firewall security check (FG-IR-22-256)
1 year 9 months ago
A vulnerability has been found in Fortinet FortiADC up to 7.4.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Application Firewall. The manipulation leads to security check for standard.
This vulnerability is known as CVE-2024-36511. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35282 | Fortinet FortiClientiOS up to 7.2.5 sensitive information in memory (FG-IR-24-139)
1 year 9 months ago
A vulnerability was found in Fortinet FortiClientiOS up to 7.2.5. It has been classified as problematic. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information in memory.
This vulnerability is uniquely identified as CVE-2024-35282. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42423 | Dell Wyse Proprietary OS 2311/2402 Citrix Workspace App authorization (dsa-2024-229)
1 year 9 months ago
A vulnerability was found in Dell Wyse Proprietary OS 2311/2402. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Citrix Workspace App. The manipulation leads to incorrect authorization.
This vulnerability is known as CVE-2024-42423. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2023-51367 | QNAP QTS/QuTS hero prior 5.1.6.2722 Build 20240402 buffer overflow (qsa-24-20)
1 year 9 months ago
A vulnerability was found in QNAP QTS and QuTS hero 4.5.4.2790 Build 20240605/5.1.3.2578 Build 20231110/5.1.4.2596 Build 20231128 and classified as critical. This issue affects some unknown processing. The manipulation leads to buffer overflow.
The identification of this vulnerability is CVE-2023-51367. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Mitiga Cloud MDR detects threats in SaaS and cloud environments
1 year 9 months ago
Mitiga unveiled its Cloud Managed Detection and Response (MDR) service, designed to provide 24/7 protection against the increasingly complex threats targeting cloud and SaaS environments. This comprehensive solution enables organizations to detect, prioritize, and respond to threats in SaaS and Cloud environments in real-time, significantly reducing alert fatigue and strengthening Security Operations (SecOps) capabilities. As yet another testament to its innovative approach to detection and response in the cloud, Mitiga has been named a finalist … More →
The post Mitiga Cloud MDR detects threats in SaaS and cloud environments appeared first on Help Net Security.
Industry News
CVE-2007-2544 | PHP TopTree BBS up to 2.0.1a tpl_message.php right_file file inclusion (EDB-3854 / XFDB-34107)
1 year 9 months ago
A vulnerability was found in PHP TopTree BBS up to 2.0.1a. It has been rated as critical. Affected by this issue is some unknown functionality of the file templates/default/tpl_message.php. The manipulation of the argument right_file leads to file inclusion.
This vulnerability is handled as CVE-2007-2544. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
丈八网安获5000万元B轮融资 将加速网络仿真技术创新及应用实践
1 year 9 months ago
拓宽产品方向、丰富应用场景,推动网络仿真普适化发展进程。