Aggregator
Redline、Meta infostealer 恶意软件操作的网络基础设施被查获
1 year 8 months ago
胡金鱼
Linus Torvalds 用电动汽车取代了燃油汽车
1 year 8 months ago
Linux 作者 Linus Torvalds 在维也纳举行的开源峰会上接受采访时表示,他抛弃了传统的内燃机汽车,用一辆沃尔沃的电动汽车取代了它。他称自己不喜欢内燃机,电动汽车驾驶起来更有趣,他对自动驾驶没什么兴趣。电动汽车配备的辅助驾驶系统能车道跟随,制造更简单。厂商不需要十年经验就能造出优秀的电动马达,传统汽车马达的零部件数量相比电动马达高出两个级别。他认为车载系统运行的是 Linux,但无疑去修改它。沃尔沃电动汽车运行的操作系统是 VolvoCars.OS,底层系统包括了 Android Automotive、OS、Autosar 和 Linux。Torvalds 表示他不是汽车迷,汽车对于他就是一个方便的工具。
品牌创新落地多项领先 默安入选软件供应链安全十大代表性厂商
1 year 8 months ago
首个软件供应链安全国家标准正式实施之日
CISA Warns of Critical Software Vulnerabilities in Industrial Devices
1 year 8 months ago
Multiple vulnerabilities in Rockwell Automation and Mitsubishi products could allow ICS cyber-attacks
每周勒索威胁摘要
1 year 8 months ago
1. Play勒索团伙公布新的受害公司
2. RansomHub勒索团伙公布新的受害公司
3. Cactus勒索团伙入侵洛杉矶市住房管理局
CVE-2024-26885 | Linux Kernel up to 6.8.1 max_entries buffer overflow (Nessus ID 210006)
1 year 8 months ago
A vulnerability was found in Linux Kernel up to 6.8.1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument max_entries leads to buffer overflow.
This vulnerability is handled as CVE-2024-26885. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47668 | Linux Kernel up to 6.10.9 lib/generic-radix-tree.c __genradix_ptr_alloc allocation of resources (Nessus ID 210006)
1 year 8 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.10.9. This issue affects the function __genradix_ptr_alloc in the library lib/generic-radix-tree.c. The manipulation leads to allocation of resources.
The identification of this vulnerability is CVE-2024-47668. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10214 | Mattermost up to 9.5.9/9.11.1 Desktop SSO incorrect implementation of authentication algorithm (Nessus ID 210009)
1 year 8 months ago
A vulnerability has been found in Mattermost up to 9.5.9/9.11.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Desktop SSO. The manipulation leads to incorrect implementation of authentication algorithm.
This vulnerability is known as CVE-2024-10214. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-9490 | Apache HTTP Server up to 2.4.43 HTTP/2 Request request smuggling (Nessus ID 210018)
1 year 8 months ago
A vulnerability classified as problematic has been found in Apache HTTP Server. This affects an unknown part of the component HTTP2 Request Handler. The manipulation leads to http request smuggling.
This vulnerability is uniquely identified as CVE-2020-9490. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2020-11984 | Oracle ZFS Storage Appliance Kit 8.8 Operating System Image buffer overflow (Nessus ID 210018)
1 year 8 months ago
A vulnerability was found in Oracle ZFS Storage Appliance Kit 8.8. It has been rated as very critical. Affected by this issue is some unknown functionality of the component Operating System Image. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2020-11984. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Олимпиада в прицеле: ФБР предупреждает о новой тактике иранских хакеров
1 year 8 months ago
Спецслужбы раскрыли план информационной битвы с помощью табло в Париже.
只要4行代码,就解决了 Windows 窗口置顶难题?
1 year 8 months ago
Боевая летопись Австралии: ученые измерили мощь аборигенского оружия
1 year 8 months ago
В чем секреты смертоносных ударов коджа и лэнгла?
新型修狗网络钓鱼工具包横扫英国、美国、日本和澳大利亚主要领域
1 year 8 months ago
安全客
CVE-2024-10652 | Changing Information Technology IDExpert up to 2.8 cross site scripting
1 year 8 months ago
A vulnerability was found in Changing Information Technology IDExpert up to 2.8. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10652. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10651 | Changing Information Technology IDExpert up to 2.8 Administrator Interface absolute path traversal
1 year 8 months ago
A vulnerability was found in Changing Information Technology IDExpert up to 2.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Administrator Interface. The manipulation leads to absolute path traversal.
This vulnerability is known as CVE-2024-10651. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10653 | Changing Information Technology IDExpert up to 2.8 Administrator Interface os command injection
1 year 8 months ago
A vulnerability was found in Changing Information Technology IDExpert up to 2.8. It has been classified as very critical. Affected is an unknown function of the component Administrator Interface. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-10653. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
助力区域创新发展系列活动|“工业征途·安全守护”工业领域数据安全实践与创新论坛成功举办
1 year 8 months ago
企业资讯
CVE-2017-2451 | Apple iOS up to 10.2 Security memory corruption (HT207617 / EDB-40961)
1 year 8 months ago
A vulnerability was found in Apple iOS up to 10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Security. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-2451. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com