Aggregator
五角大楼的"秘密武器"!当AI开始读懂机密情报
1 month 2 weeks ago
当OpenAI的工程师第一次进入五角大楼的机密网络时,他们看到的景象令人震撼。
Altman 或官宣 OpenAI 硬件;李想谈 L9 4 年才换代:汽车非手机,AI 帮助有限;多家车企否认「被约谈」 | 极客早知道
1 month 2 weeks ago
特斯拉 Model Y 成首款通过美国全新驾驶辅助安全基准的车型;揽派一体,京东快递行业内首推「顺手寄」服务;英伟达今年已承诺投入 400 亿美元押注 AI 股权投资
诚邀渠道合作伙伴共启新征程
1 month 2 weeks ago
母亲节 | 世界虽大 总有您温暖的守候
1 month 2 weeks ago
母亲节 | 世界虽大 总有您温暖的守候
谈谈我对VMProtect代码保护”通解”的一点看法
1 month 2 weeks ago
偶然一阵醒意袭来,偶然进到论坛看到有两篇关于VMProtect的技术文章让我想起了多年以前我也曾花了一段时间研究过VMProtect还写了不少相关的代码,于是惊坐起翻起了许久未曾改过的相关代码仓库甚是感慨遂有了这篇文章
What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do
1 month 2 weeks ago
The Instructure Canvas breach affects universities, K–12 school districts, and teaching hospitals globally. This blog entry intends to provide context and practical guidance.
Johnny Hand
Fulcrum
1 month 2 weeks ago
You must login to view this content
cohenido
CVE-2018-8779 | Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0 UNIXServer.open/UNIXSocket.open Null Character input validation (RHSA-2018:3729 / Nessus ID 109284)
1 month 2 weeks ago
A vulnerability described as critical has been identified in Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0. Affected by this issue is the function UNIXServer.open/UNIXSocket.open. Executing a manipulation as part of Null Character can lead to improper input validation.
This vulnerability is handled as CVE-2018-8779. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2018-8778 | Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0 String#unpack information disclosure (RHSA-2018:3729 / Nessus ID 109284)
1 month 2 weeks ago
A vulnerability marked as critical has been reported in Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0. Affected by this vulnerability is the function String#unpack. Performing a manipulation results in information disclosure.
This vulnerability is known as CVE-2018-8778. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2018-8778 | Apple macOS up to 10.14.0 Ruby format string (HT209193 / Nessus ID 111081)
1 month 2 weeks ago
A vulnerability marked as critical has been reported in Apple macOS up to 10.14.0. This impacts an unknown function of the component Ruby. Performing a manipulation results in format string.
This vulnerability was named CVE-2018-8778. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2018-8777 | Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0 WEBrick Server HTTP Request resource management (USN-3685-1 / Nessus ID 110551)
1 month 2 weeks ago
A vulnerability labeled as problematic has been found in Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0. Affected is an unknown function of the component WEBrick Server. Such manipulation as part of HTTP Request leads to improper resource management.
This vulnerability is traded as CVE-2018-8777. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2018-8777 | Apple macOS up to 10.14.0 Ruby resource consumption (HT209193 / Nessus ID 111081)
1 month 2 weeks ago
A vulnerability labeled as critical has been found in Apple macOS up to 10.14.0. This affects an unknown function of the component Ruby. Such manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2018-8777. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2018-6914 | Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0 Dirmktmpdir prefix path traversal (RHSA-2018:3729 / Nessus ID 109284)
1 month 2 weeks ago
A vulnerability categorized as critical has been discovered in Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0. This affects the function Dirmktmpdir. The manipulation of the argument prefix with the input .. results in path traversal.
This vulnerability is reported as CVE-2018-6914. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2018-6914 | Apple macOS up to 10.14.0 Ruby path traversal (HT209193 / Nessus ID 111081)
1 month 2 weeks ago
A vulnerability identified as critical has been detected in Apple macOS up to 10.14.0. The impacted element is an unknown function of the component Ruby. This manipulation causes path traversal.
This vulnerability is handled as CVE-2018-6914. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2017-17742 | Apple macOS up to 10.14.0 Ruby response splitting (HT209193 / Nessus ID 111081)
1 month 2 weeks ago
A vulnerability categorized as critical has been discovered in Apple macOS up to 10.14.0. The affected element is an unknown function of the component Ruby. The manipulation results in http response splitting.
This vulnerability is known as CVE-2017-17742. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2017-17742 | Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0 HTTP Server HTTP Response Split response splitting (USN-3685-1 / Nessus ID 110551)
1 month 2 weeks ago
A vulnerability labeled as critical has been found in Ruby up to 2.2.9/2.3.6/2.4.3/2.5.0. This issue affects some unknown processing of the component HTTP Server. Executing a manipulation as part of HTTP Response can lead to http response splitting (Split).
This vulnerability is handled as CVE-2017-17742. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2019-16255 | Ruby up to 2.4.7/2.5.6/2.6.4 lib/shell.rb Argument injection (DLA 2027-1 / WID-SEC-2023-1110)
1 month 2 weeks ago
A vulnerability was found in Ruby up to 2.4.7/2.5.6/2.6.4. It has been declared as critical. Impacted is an unknown function in the library lib/shell.rb. Executing a manipulation as part of Argument can lead to injection.
The identification of this vulnerability is CVE-2019-16255. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2019-16254 | Ruby up to 2.4.7/2.5.6/2.6.4 Incomplete Fix HTTP Response injection (DLA 2027-1 / WID-SEC-2023-1110)
1 month 2 weeks ago
A vulnerability was found in Ruby up to 2.4.7/2.5.6/2.6.4. It has been classified as critical. This issue affects some unknown processing of the component Incomplete Fix. Performing a manipulation as part of HTTP Response results in injection.
This vulnerability was named CVE-2019-16254. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2022-26651 | Digium Asterisk/Certified Asterisk up to 16.8-cert13/16.25.1/18.11.1/19.3.1 func_odbc sql injection (AST-2022-003 / EUVD-2022-31204)
1 month 2 weeks ago
A vulnerability was found in Digium Asterisk and Certified Asterisk up to 16.8-cert13/16.25.1/18.11.1/19.3.1 and classified as critical. This issue affects the function func_odbc. Such manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2022-26651. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com