Aggregator
CVE-2004-1464 | Cisco IOS up to 12.0(3) Telnet TCP Connection denial of service (VU#384230 / Nessus ID 15627)
CVE-2004-1472 | Symantec Firewall/VPN 100/200/200R UDP Portscan denial of service (VU#441078 / ID 78045)
CVE-2004-1457 | Novell BorderManager 3.8 denial of service (VU#432097 / XFDB-16697)
CVE-2004-1456 | Cvstrac 1.1/1.1.1/1.1.2/1.1.3 rcsinfo privileges management (VU#770816 / EDB-379)
CVE-2004-1454 | Cisco IOS up to 12.3XE OSPF Packet denial of service (VU#989406 / Nessus ID 14337)
CVE-2004-1448 | Jetbox One CMS 2.0.8 memory corruption (VU#417408 / XFDB-16900)
【公告】JSRC九月英雄榜单揭晓
【活动】双十一回血活动开启,单个漏洞奖励可达4万+!
CSA GCR 2024 | 百度安全DDoS防护服务荣获安全磐石奖等多项殊荣
Fog
CVE-2004-1016 | Linux Kernel 2.4.x sendmsg deadlock (EDB-685 / Nessus ID 16303)
Цукерберг в осаде: мошенники захватили 21 млн пользователей BlueSky
10 Most Impactful PAM Use Cases for Enhancing Organizational Security
Пароли в завещании: японская инициатива для упрощения жизни после смерти
Qilin
Qilin
North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs
N-able Strengthens Cybersecurity via $266M Adlumin Purchase
With Adlumin’s cloud-native XDR and MDR services, N-able consolidates its position as a leader in IT management. Buying the Washington D.C.-based security operations vendor for up to $266 million drives value through AI-powered threat detection and compliance solutions tailored for MSPs.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2024-44308 Apple Multiple Products Code Execution Vulnerability
- CVE-2024-44309 Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
- CVE-2024-21287 Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
Users and administrators are also encouraged to review the Palo Alto Threat Brief: Operation Lunar Peek related to CVE-2024-0012, the Palo Alto Security Bulletin for CVE-2024-0012, and the Palo Alto Security Bulletin for CVE-2024-9474 for additional information.
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.