Aggregator
CVE-1999-0314 | SGI IRIX 6.4 ioconfig Local Privilege Escalation (EDB-19163 / XFDB-1199)
1 year 9 months ago
A vulnerability classified as critical has been found in SGI IRIX 6.4. Affected is an unknown function of the file ioconfig. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-1999-0314. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
不是每一块钱的收入都一样:哪家网络安全上市公司更受市场青睐
1 year 9 months ago
上半年A股网络安全公司财报显示,行业整体营收出现下滑,市场仍处于不确定性中。本文深入分析了网络安全行业的估值指标,如市盈率(P/E)、市销率(P/S)和企业价值倍数(EV/EBITDA),并讨论了基于EV/Sales(TTM)的公司排名。
不是每一块钱的收入都一样:哪家网络安全上市公司更受市场青睐
1 year 9 months ago
上半年A股网络安全公司财报显示,行业整体营收出现下滑,市场仍处于不确定性中。本文深入分析了网络安全行业的估值指标,如市盈率(P/E)、市销率(P/S)和企业价值倍数(EV/EBITDA),并讨论了基于EV/Sales(TTM)的公司排名。
Inside CISA's Unprecedented Election Security Mission
1 year 9 months ago
CISA 'Committing More Resources Than Ever Before' to Election Infrastructure
The Cybersecurity and Infrastructure Security Agency told Information Security Media Group it is in the process of carrying out its most expansive national effort to secure election infrastructure across the country ahead of the upcoming November election.
The Cybersecurity and Infrastructure Security Agency told Information Security Media Group it is in the process of carrying out its most expansive national effort to secure election infrastructure across the country ahead of the upcoming November election.
Brazil Suspends Access to Elon Musk's X, Including via VPNs
1 year 9 months ago
Supreme Court Panel Upholds Ban, After X Failed to Appoint a Legal Representative
Brazil has begun blocking domestic access to social platform X - including criminalizing access by Brazilians who might use a VPN - after the company failed to comply with court orders tied to combating disinformation campaigns, and a law requiring it has a legal representative in the country.
Brazil has begun blocking domestic access to social platform X - including criminalizing access by Brazilians who might use a VPN - after the company failed to comply with court orders tied to combating disinformation campaigns, and a law requiring it has a legal representative in the country.
North Korean Hackers Tied to Exploits of Chromium Zero-Day
1 year 9 months ago
Cryptocurrency Users Targeted in Latest Campaign Involving FudModule Rootkit
A hacking group tied to North Korea exploited a zero-day vulnerability in the open source Google Chromium web browser to try and steal cryptocurrency, Microsoft said. The attack campaign is the latest to involve a sophisticated North Korean rootkit called FudModule. Google has fixed the flaw.
A hacking group tied to North Korea exploited a zero-day vulnerability in the open source Google Chromium web browser to try and steal cryptocurrency, Microsoft said. The attack campaign is the latest to involve a sophisticated North Korean rootkit called FudModule. Google has fixed the flaw.
How AI Goes Rogue
1 year 9 months ago
This is the second blog in an ongoing series on Rogue AI. Keep following for more technical guidance, case studies, and insights.
AI Team
CVE-2018-15534 | Geutebrueck re_porter 16 up to 7.8 Service Port 12003 /statistics/gscsetup.xml Username information disclosure (ID 149002 / EDB-45240)
1 year 9 months ago
A vulnerability was found in Geutebrueck re_porter 16 up to 7.8. It has been classified as problematic. Affected is an unknown function of the file /statistics/gscsetup.xml of the component Service Port 12003. The manipulation leads to information disclosure (Username).
This vulnerability is traded as CVE-2018-15534. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-1843 | Maptools MapLab 2.2.1 gmapfactory/params.php gszAppPath code injection (EDB-3638 / XFDB-33360)
1 year 9 months ago
A vulnerability was found in Maptools MapLab 2.2.1. It has been classified as critical. Affected is an unknown function of the file gmapfactory/params.php. The manipulation of the argument gszAppPath leads to code injection.
This vulnerability is traded as CVE-2007-1843. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-17020 | D-Link DCS-5009/DCS-5010/DCS-5020L alphapd /setSystemAdmin AdminID command injection (EDB-44580)
1 year 9 months ago
A vulnerability classified as critical has been found in D-Link DCS-5009, DCS-5010 and DCS-5020L. Affected is an unknown function of the file /setSystemAdmin of the component alphapd. The manipulation of the argument AdminID leads to command injection.
This vulnerability is traded as CVE-2017-17020. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-1999-1461 | SGI IRIX up to 6.5.10 inpview Local Privilege Escalation (EDB-19304 / BID-381)
1 year 9 months ago
A vulnerability classified as critical was found in SGI IRIX up to 6.5.10. This vulnerability affects unknown code of the component inpview. The manipulation leads to Local Privilege Escalation.
This vulnerability was named CVE-1999-1461. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-6991 | Apple iOS up to 10.3.1 SQLite memory corruption (HT207798 / Nessus ID 100270)
1 year 9 months ago
A vulnerability, which was classified as critical, has been found in Apple iOS up to 10.3.1. Affected by this issue is some unknown functionality of the component SQLite. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-6991. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Making progress on routing security: the new White House roadmap
1 year 9 months ago
On September 3, 2024, the White House published a report on Internet routing security. We’ll talk about what that means and how you can help.
Mike Conlow
CVE-2007-1806 | Red Mexico RM+Soft Gallery 1.0 categos.php idcat sql injection (EDB-3633 / XFDB-33370)
1 year 9 months ago
A vulnerability classified as critical has been found in Red Mexico RM+Soft Gallery 1.0. Affected is an unknown function of the file categos.php. The manipulation of the argument idcat leads to sql injection.
This vulnerability is traded as CVE-2007-1806. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-5838 | 6677g Girls Games - Shoes Maker 1.0.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 9 months ago
A vulnerability classified as critical has been found in 6677g Girls Games - Shoes Maker 1.0.1. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-5838. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
Introducing Goffloader: A Pure Go Implementation of an In-Memory COFFLoader and PE Loader
1 year 9 months ago
We are excited to announce the release of Goffloader, a pure Go implementation of an in-memory COFFLoader and PE loader. This tool is designed to facilitate the easy execution of Cobalt Strike BOFs and unmanaged PE files directly in memory without writing any files to disk. Goffloader aims to take functionality that is conventionally within […]
The post Introducing Goffloader: A Pure Go Implementation of an In-Memory COFFLoader and PE Loader appeared first on Praetorian.
The post Introducing Goffloader: A Pure Go Implementation of an In-Memory COFFLoader and PE Loader appeared first on Security Boulevard.
Nathan Sportsman
CVE-2014-5837 | Game-insight My Railway 1.1.33 X.509 Certificate cryptographic issues (VU#582497)
1 year 9 months ago
A vulnerability was found in Game-insight My Railway 1.1.33. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-5837. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2007-1807 | Peak Xoops Myalbum P up to 2.0 viewcat.php cid sql injection (EDB-3632 / XFDB-33371)
1 year 9 months ago
A vulnerability classified as critical was found in Peak Xoops Myalbum P up to 2.0. Affected by this vulnerability is an unknown functionality of the file viewcat.php. The manipulation of the argument cid leads to sql injection.
This vulnerability is known as CVE-2007-1807. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2005-1237 | China-on-site FlexPHPNews 0.0.3 news.php newsid sql injection (EDB-3631 / XFDB-20214)
1 year 9 months ago
A vulnerability was found in China-on-site FlexPHPNews 0.0.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file news.php. The manipulation of the argument newsid leads to sql injection.
This vulnerability is handled as CVE-2005-1237. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com