Aggregator
How to defend against brute force and password spray attacks
1 year 9 months ago
While not very sophisticated, brute force password attacks pose a significant threat to an organization's security. Learn more from Specops Software about these types of attacks and how to defend against them. [...]
Sponsored by Specops Software
CVE-2016-9243 | cryptography up to 1.5.1 HKDF input validation (FEDORA-2016-2d90e27e50 / Nessus ID 94994)
1 year 9 months ago
A vulnerability classified as critical was found in cryptography up to 1.5.1. Affected by this vulnerability is an unknown functionality of the component HKDF. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2016-9243. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33202 | Bouncy Castle for Java up to 1.72 ASN.1 org.bouncycastle.openssl.PEMParser denial of service
1 year 9 months ago
A vulnerability classified as problematic was found in Bouncy Castle for Java up to 1.72. This vulnerability affects the function org.bouncycastle.openssl.PEMParser of the component ASN.1 Handler. The manipulation leads to denial of service.
This vulnerability was named CVE-2023-33202. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38631 | Linux Kernel up to 6.9.3 PAC1934 array index (8dbcb3a8cfdf/51fafb3cd7fc)
1 year 9 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.9.3. Affected by this issue is some unknown functionality of the component PAC1934. The manipulation leads to improper validation of array index.
This vulnerability is handled as CVE-2024-38631. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38633 | Linux Kernel up to 6.9.3 max3100 uart_register_driver null pointer dereference
1 year 9 months ago
A vulnerability has been found in Linux Kernel up to 6.9.3 and classified as critical. This vulnerability affects the function uart_register_driver of the component max3100. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-38633. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37185 | OpenHarmony up to 4.0.1 Pre-installed Apps out-of-bounds write
1 year 9 months ago
A vulnerability was found in OpenHarmony up to 4.0.1 and classified as critical. Affected by this issue is some unknown functionality of the component Pre-installed Apps. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2024-37185. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-37077 | OpenHarmony up to 4.0.1 Pre-installed Apps out-of-bounds write
1 year 9 months ago
A vulnerability classified as critical has been found in OpenHarmony up to 4.0.1. Affected is an unknown function of the component Pre-installed Apps. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2024-37077. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-45038 | QNAP Music Station up to 5.3.x improper authentication (qsa-24-25)
1 year 9 months ago
A vulnerability was found in QNAP Music Station up to 5.3.x and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2023-45038. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-47563 | QNAP Video Station up to 5.8.1 os command injection (qsa-24-24)
1 year 9 months ago
A vulnerability was found in QNAP Video Station up to 5.8.1. It has been classified as critical. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2023-47563. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-39298 | QNAP QTS/QuTS hero/QuTScloud authorization (qsa-24-28)
1 year 9 months ago
A vulnerability classified as critical has been found in QNAP QTS, QuTS hero and QuTScloud. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2023-39298. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
How to Establish & Enhance Endpoint Security
1 year 9 months ago
Endpoint security has been around for decades, but changes in device use and the quick evolution of new attacks have triggered the development of new security techniques.
Eric Grenier
9th September – Threat Intelligence Report
1 year 9 months ago
For the latest discoveries in cyber research for the week of 9th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The German air traffic control agency, Deutsche Flugsicherung, has confirmed a cyberattack that impacted its administrative IT infrastructure. The extent of data accessed is still under investigation, and flight operations remained unaffected. […]
The post 9th September – Threat Intelligence Report appeared first on Check Point Research.
lorenf
Tropic Trooper: хакеры теперь сеют хаос на Ближнем Востоке
1 year 9 months ago
Эксперты Kaspersky выявили новую кампанию группировки.
CVE-2017-13051 | Apple macOS up to 10.13.1 tcpdump memory corruption (HT208221 / Nessus ID 100472)
1 year 9 months ago
A vulnerability classified as very critical has been found in Apple macOS up to 10.13.1. Affected is an unknown function of the component tcpdump. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2017-13051. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37351 | Absolute Secure Access up to 13.05 Management UI cross site scripting
1 year 9 months ago
A vulnerability has been found in Absolute Secure Access up to 13.05 and classified as problematic. This vulnerability affects unknown code of the component Management UI. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-37351. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37352 | Absolute Secure Access up to 13.05 Management UI cross site scripting
1 year 9 months ago
A vulnerability was found in Absolute Secure Access up to 13.05 and classified as problematic. This issue affects some unknown processing of the component Management UI. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-37352. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36478 | Linux Kernel up to 6.9.3 null_blk nullb0 del_gendisk null pointer dereference (5d0495473ee4/a2db328b0839)
1 year 9 months ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.9.3. Affected by this issue is the function del_gendisk of the file /sys/kernel/config/nullb/nullb0 of the component null_blk. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-36478. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36489 | Linux Kernel up to 5.10.218/5.15.160/6.1.92/6.6.32/6.9.3 tls_init initialization
1 year 9 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 5.10.218/5.15.160/6.1.92/6.6.32/6.9.3. This affects the function tls_init. The manipulation leads to improper initialization.
This vulnerability is uniquely identified as CVE-2024-36489. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38390 | Linux Kernel up to 6.1.92/6.6.32/6.9.3 a6xx_destroy null pointer dereference
1 year 9 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.92/6.6.32/6.9.3. Affected is the function a6xx_destroy. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-38390. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com