Aggregator
2025年数据安全防护与智能治理教育部重点实验室开放课题
10 months 2 weeks ago
申请受理的截止日期为2025年7月25日
2024年团队奖金来啦~EduSRC年度第一!
10 months 2 weeks ago
闲云潭影日悠悠,物换星移几度秋。感谢各位团队师傅的关注和支持,经过2024年大家的辛勤付出,我们团队取得了EduSRC平台的年度安全团队第一名!!!
CVE-2007-1458 | CARE2X inc_config_color.php root_path privileges management (EDB-3472 / XFDB-32981)
10 months 2 weeks ago
A vulnerability classified as critical has been found in CARE2X. This affects an unknown part of the file inc_config_color.php. The manipulation of the argument root_path leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2007-1458. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Identity & SSO Compliance: GDPR, Certifications, and How to Keep It Clean
10 months 2 weeks ago
Introduction Let’s be honest — nobody loves dealing with compliance. It usually sounds like a bunch of paperwork and legal jargon no one asked for. But when it comes to identity systems and Single Sign-On (SSO), it’s actually a big deal. Why? Because identity systems handle your users’ most personal stuff: their names, emails, IDs,...
The post Identity & SSO Compliance: GDPR, Certifications, and How to Keep It Clean appeared first on Security Boulevard.
Devesh Patel
CVE-2007-1458 | CARE2X 1.1 inc_checkdate_lang.php root_path file inclusion (EDB-3472 / XFDB-32981)
10 months 2 weeks ago
A vulnerability was found in CARE2X 1.1. It has been rated as critical. This issue affects some unknown processing of the file inc_checkdate_lang.php. The manipulation of the argument root_path leads to file inclusion.
The identification of this vulnerability is CVE-2007-1458. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5878 | ESAPI esapi-java-legacy up to 2.6.2.0 SQL Injection Defense Encoder.encodeForSQL special element
10 months 2 weeks ago
A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the function Encoder.encodeForSQL of the component SQL Injection Defense. The manipulation leads to improper neutralization of special elements.
The identification of this vulnerability is CVE-2025-5878. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
The project was contacted early about this issue and handled it with an exceptional level of professionalism. In the new release the feature was disabled by default and any attempt to use it will trigger a warning. Furthermore, the misleading Java class documentation was updated to warn about the risks.
vuldb.com
CVE-2025-6858 | HDF5 1.14.6 src/H5Centry.c H5C__flush_single_entry null pointer dereference (Issue 5576 / EUVD-2025-19482)
10 months 2 weeks ago
A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flush_single_entry of the file src/H5Centry.c. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-6858. The attack needs to be approached locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-57648 | openlink virtuoso-opensource 7.2.11 itc_set_param_row denial of service (Issue 1195 / EUVD-2024-53680)
10 months 2 weeks ago
A vulnerability was found in openlink virtuoso-opensource 7.2.11. It has been rated as problematic. This issue affects some unknown processing of the component itc_set_param_row. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2024-57648. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-57643 | openlink virtuoso-opensource 7.2.11 box_deserialize_string denial of service (Issue 1181 / EUVD-2024-53675)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in openlink virtuoso-opensource 7.2.11. This issue affects some unknown processing of the component box_deserialize_string. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2024-57643. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-57644 | openlink virtuoso-opensource 7.2.11 itc_hash_compare denial of service (Issue 1193 / EUVD-2024-53676)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in openlink virtuoso-opensource 7.2.11. Affected is an unknown function of the component itc_hash_compare. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-57644. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-57645 | openlink virtuoso-opensource 7.2.11 component denial of service (Issue 1197 / EUVD-2024-53677)
10 months 2 weeks ago
A vulnerability has been found in openlink virtuoso-opensource 7.2.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Component. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-57645. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-57646 | openlink virtuoso-opensource 7.2.11 psiginfo denial of service (Issue 1199 / EUVD-2024-53678)
10 months 2 weeks ago
A vulnerability was found in openlink virtuoso-opensource 7.2.11 and classified as problematic. Affected by this issue is some unknown functionality of the component psiginfo. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-57646. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-57647 | openlink virtuoso-opensource 7.2.11 row_insert_cast denial of service (Issue 1207 / EUVD-2024-53679)
10 months 2 weeks ago
A vulnerability was found in openlink virtuoso-opensource 7.2.11. It has been classified as problematic. This affects an unknown part of the component row_insert_cast. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-57647. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-57642 | openlink virtuoso-opensource 7.2.11 dfe_inx_op_col_def_table denial of service (Issue 1191 / EUVD-2024-53674)
10 months 2 weeks ago
A vulnerability classified as problematic was found in openlink virtuoso-opensource 7.2.11. This vulnerability affects unknown code of the component dfe_inx_op_col_def_table. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-57642. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-57636 | openlink virtuoso-opensource 7.2.11 SQL itc_sample_row_check denial of service (Issue 1194 / EUVD-2024-53668)
10 months 2 weeks ago
A vulnerability classified as problematic was found in openlink virtuoso-opensource 7.2.11. Affected by this vulnerability is the function itc_sample_row_check of the component SQL Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-57636. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-57637 | openlink virtuoso-opensource 7.2.11 SQL dfe_unit_gb_dependant denial of service (Issue 1192 / EUVD-2024-53669)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in openlink virtuoso-opensource 7.2.11. Affected by this issue is the function dfe_unit_gb_dependant of the component SQL Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-57637. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-57638 | openlink virtuoso-opensource 7.2.11 SQL dfe_body_copy denial of service (Issue 1190 / EUVD-2024-53670)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in openlink virtuoso-opensource 7.2.11. This affects the function dfe_body_copy of the component SQL Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-57638. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-57639 | openlink virtuoso-opensource 7.2.11 SQL dc_elt_size denial of service (Issue 1185 / EUVD-2024-53671)
10 months 2 weeks ago
A vulnerability was found in openlink virtuoso-opensource 7.2.11. It has been declared as problematic. Affected by this vulnerability is the function dc_elt_size of the component SQL Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-57639. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-57640 | openlink virtuoso-opensource 7.2.11 SQL dc_add_int denial of service (Issue 1184 / EUVD-2024-53672)
10 months 2 weeks ago
A vulnerability was found in openlink virtuoso-opensource 7.2.11. It has been rated as problematic. Affected by this issue is the function dc_add_int of the component SQL Handler. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-57640. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com