Aggregator
【资料】全球动态-新增中国台湾省、韩国
9 months 1 week ago
中国台湾省近24小时(2025年07月05日)发展动态的分析报告 一、总体概要 过去24小时内,中国台湾省的动
【资料】以色列的暗杀和隐蔽行动
9 months 1 week ago
《核武器重要吗:彭培奥如何应对伊朗》这篇文章探讨了核武器在国际关系中的重要性,以及美国如何应对伊朗的核威胁。
CVE-2024-5953 | 389-ds-base Hash userPassword denial of service (EUVD-2024-47135 / Nessus ID 207920)
9 months 1 week ago
A vulnerability classified as problematic was found in 389-ds-base. This vulnerability affects unknown code of the component Hash Handler. The manipulation of the argument userPassword leads to denial of service.
This vulnerability was named CVE-2024-5953. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9979 | PyO3 up to 0.22.3 Reference use after free (EUVD-2024-2969)
9 months 1 week ago
A vulnerability has been found in PyO3 up to 0.22.3 and classified as problematic. This vulnerability affects unknown code of the component Reference Handler. The manipulation leads to use after free.
This vulnerability was named CVE-2024-9979. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0678 | GNU grub2 squash4 out-of-bounds write (EUVD-2025-5569 / Nessus ID 216508)
9 months 1 week ago
A vulnerability classified as critical was found in GNU grub2. Affected by this vulnerability is an unknown functionality of the component squash4. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2025-0678. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-5148 | GNOME gnome-remote-desktop Session Agent information disclosure (EUVD-2024-47138)
9 months 1 week ago
A vulnerability classified as problematic has been found in GNOME gnome-remote-desktop. Affected is an unknown function of the component Session Agent Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-5148. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-0689 | GNU grub2 udf grub_udf_read_block heap-based overflow (EUVD-2025-5596 / Nessus ID 216508)
9 months 1 week ago
A vulnerability was found in GNU grub2 and classified as critical. This issue affects the function grub_udf_read_block of the component udf. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2025-0689. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2025-1125 | GNU grub2 hfs out-of-bounds write (EUVD-2025-5597 / Nessus ID 216508)
9 months 1 week ago
A vulnerability was found in GNU grub2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component hfs. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2025-1125. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
Cursor就定价模糊问题道歉 同时将按使用次数定价换成按使用量定价
9 months 1 week ago
人工智能编程开发助手Cursor因定价变更引发争议后致歉,并调整订阅方案:新版Cursor Pro采用按使用量计费,新增无限使用的Auto模式及每月20美元先进模型调用额度;超出额度后按成本价计费,并可设置消费上限避免高额账单。
RCE через Game Pass: тысячи ПК взломаны через Call of Duty
9 months 1 week ago
Удалённый взлом превращает Call of Duty в поле для атак.
CVE-2006-1504 | Arab Portal download.php Title cross site scripting (EDB-27501 / XFDB-25515)
9 months 1 week ago
A vulnerability has been found in Arab Portal and classified as problematic. This vulnerability affects unknown code of the file download.php. The manipulation of the argument Title leads to basic cross site scripting.
This vulnerability was named CVE-2006-1504. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
[最后30天] CV优质域名半价折上折活动即将结束 通过蓝点网优惠券可4.5折注册
9 months 1 week ago
CV域名促销活动即将于7月底结束,优质域名可享半价优惠并叠加蓝点网10%折扣券。单字母域名如k.cv现价4506.75美元。活动结束后价格恢复原价。目前可注册的单字母域名包括h.cv、k.cv等,其他优质域名如vip.cv、ok.cv等也开放注册。
Имя. Телефон. Вся жизнь. На блюдечке с голубой каёмочкой.
9 months 1 week ago
Фишинг, доксинг, скам: что ждёт тех, чьи резюме попали не в те руки?
Taiwan NSB Alerts Public on Data Risks from Douyin, Weibo, and RedNote Over China Ties
9 months 1 week ago
Taiwan's National Security Bureau (NSB) has warned that China-developed applications like RedNote (aka Xiaohongshu), Weibo, Douyin, WeChat, and Baidu Cloud pose security risks due to excessive data collection and data transfer to China.
The alert comes following an inspection of these apps carried out in coordination with the Ministry of Justice Investigation Bureau (MJIB) and the Criminal
The Hacker News
Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties
9 months 1 week ago
台湾国安局警告中国大陆开发的应用如小红书、微博等存在安全风险,过度收集数据并传回中国。这些应用违反多项安全指标,涉及个人信息和设备信息的获取。其他国家也已对类似应用采取限制措施。
Физики нарушили закон Кирхгофа, не нарушив ни одного фундаментального принципа
9 months 1 week ago
Метаматериалы переворачивают привычную нам физику.
3 CVE + 1 руткит = китайцы за 4 месяца обчистили пол-Европы
9 months 1 week ago
Крупнейшие системы Европы стали частью чужого бизнеса, причём незаметно для владельцев.
微软宣布关闭自2000年以来的巴基斯坦业务 但后续将继续提供支持
9 months 1 week ago
微软关闭在巴基斯坦的当地业务,将其许可和商业合同转移到爱尔兰,并通过经销商和周边办事处继续为客户提供服务。此举是微软全球裁员和优化劳动力的一部分,尽管客户支持不受影响,但可能对巴基斯坦的IT发展产生不利影响。
CVE-2025-53485 | SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki SetTranslationHandler.php authorization (EUVD-2025-20087)
9 months 1 week ago
A vulnerability classified as critical was found in SecurePoll Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki. This vulnerability affects unknown code of the file SetTranslationHandler.php. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-53485. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com