Aggregator
CVE-2018-6954 | systemd up to 237 systemd-tmpfiles access control (Issue 7986 / Nessus ID 119253)
6 months 1 week ago
A vulnerability, which was classified as critical, was found in systemd up to 237. Affected is an unknown function of the component systemd-tmpfiles. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2018-6954. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-1000168 | nghttp2 up to 0.9.x/1.30.x ALTSVC Frame input validation (RHSA-2019:0366 / Nessus ID 111095)
6 months 1 week ago
A vulnerability classified as problematic was found in nghttp2 up to 0.9.x/1.30.x. Affected by this vulnerability is an unknown functionality of the component ALTSVC Frame Handler. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2018-1000168. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-1000500 | BusyBox SSL Certificate Validator certificate validation (USN-4531-1)
6 months 1 week ago
A vulnerability classified as critical was found in BusyBox. Affected by this vulnerability is an unknown functionality of the component SSL Certificate Validator. The manipulation leads to improper certificate validation.
This vulnerability is known as CVE-2018-1000500. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2018-1000517 | BusyBox wget memory corruption (USN-3935-1 / Nessus ID 111358)
6 months 1 week ago
A vulnerability classified as critical has been found in BusyBox. Affected is an unknown function of the component wget. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2018-1000517. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2018-15688 | systemd up to 239 dhcp6 Client memory corruption (RHSA-2018:3665 / EUVD-2018-7558)
6 months 1 week ago
A vulnerability was found in systemd up to 239. It has been declared as critical. This vulnerability affects unknown code of the component dhcp6 Client. The manipulation leads to memory corruption.
This vulnerability was named CVE-2018-15688. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-20679 | BusyBox up to 1.29.x udhcp common.c udhcp_get_option DHCP Message out-of-bounds (Bug 154361 / EUVD-2018-13227)
6 months 1 week ago
A vulnerability has been found in BusyBox up to 1.29.x and classified as problematic. Affected by this vulnerability is the function udhcp_get_option of the file networking/udhcp/common.c of the component udhcp. The manipulation as part of DHCP Message leads to out-of-bounds read.
This vulnerability is known as CVE-2018-20679. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-5747 | BusyBox up to 1.30.0 Incomplete Fix CVE-2018-20679 DHCP Message out-of-bounds (USN-3935-1 / EUVD-2019-15320)
6 months 1 week ago
A vulnerability, which was classified as problematic, was found in BusyBox up to 1.30.0. Affected is an unknown function of the component Incomplete Fix CVE-2018-20679. The manipulation as part of DHCP Message leads to out-of-bounds read.
This vulnerability is traded as CVE-2019-5747. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2018-15687 | systemd up to 239 chown_one race condition (USN-3816-1 / EDB-45715)
6 months 1 week ago
A vulnerability was found in systemd up to 239. It has been classified as critical. This affects the function chown_one. The manipulation leads to race condition.
This vulnerability is uniquely identified as CVE-2018-15687. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-15686 | systemd up to 239 unit_deserialize deserialization (RHSA-2019:2091 / EDB-45714)
6 months 1 week ago
A vulnerability was found in systemd up to 239 and classified as critical. Affected by this issue is the function unit_deserialize. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2018-15686. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-12900 | bzip2 up to 1.0.6 decompress.c BZ2_decompress out-of-bounds write (K68713584 / Nessus ID 210436)
6 months 1 week ago
A vulnerability was found in bzip2 up to 1.0.6. It has been classified as critical. Affected is the function BZ2_decompress of the file decompress.c. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2019-12900. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2019-12900 | Oracle Database Server 11.2.0.4/12.1.0.2/12.2.0.1/18c/19c bzip2 out-of-bounds write (Nessus ID 210436)
6 months 1 week ago
A vulnerability was found in Oracle Database Server 11.2.0.4/12.1.0.2/12.2.0.1/18c/19c. It has been rated as critical. Affected by this issue is some unknown functionality of the component bzip2. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2019-12900. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
【高级睡眠混淆技术】| Cronos
6 months 1 week ago
基于EKKO的一种睡眠变种
到 2029 年,全球运营商将在 AI 安全方面投资超过 170 亿美元
6 months 1 week ago
安全客
Да, ИИ создаёт код быстро. Но потом человек 3 часа ломает голову, как это вообще должно было работать
6 months 1 week ago
Вот она — главная проблема вайб-кодинга.
Top 5 Best Cybersecurity Companies Leading The Industry Right Now in 2025
6 months 1 week ago
If you’re shopping around for cybersecurity solutions in 2025, you’re probably feeling a little overwhelmed and not sure where to turn. Not only are there more attacks than ever before (and more sophisticated), but there are a wide range of potential security vendors that all promise to do the same thing; protect your business, its […]
The post Top 5 Best Cybersecurity Companies Leading The Industry Right Now in 2025 appeared first on Cyber Security News.
Cyber Advisory
QNAP 修复 Qsync Central 及 File Station 5 的 SQL 注入及证书验证漏洞
6 months 1 week ago
安全客
美国最高法院允许 DOGE 不受限制地访问 SSA 系统
6 months 1 week ago
安全客
CVE-2024-56898 | Geovision GV-ASWeb up to 6.1.0.0 HTTP Request access control (EDB-52189)
6 months 1 week ago
A vulnerability, which was classified as critical, has been found in Geovision GV-ASWeb up to 6.1.0.0. This issue affects some unknown processing of the component HTTP Request Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-56898. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
vuldb.com
UNITED NATURAL FOODS, INC. has Filed Form 8-K Due to a Cybersecurity Incident
6 months 1 week ago
UNITED NATURAL FOODS, INC. has Filed Form 8-K Due to a Cybersecurity Incident
Dark Web Informer - Cyber Threat Intelligence