Aggregator
CVE-2024-4360 | bdthemes Element Pack Elementor Addons Plugin up to 5.7.2 on WordPress Attribute title_tag cross site scripting
CVE-2024-0113 | NVIDIA Mellanox OS/Skyway/MetroX-3 XC/MetroX-2 URI path traversal
CVE-2024-7399 | Samsung Electronics MagicINFO 9 Server prior 21.1050 path traversal
Overcoming the 5 Biggest Challenges to Implementing Just-in-Time, Just Enough Privilege
Embracing a just-in-time and just-enough privilege approach that harnesses context and automation can remove the tension between security and productivity, enabling teams to run faster without compromising on security standards.
The post Overcoming the 5 Biggest Challenges to Implementing Just-in-Time, Just Enough Privilege appeared first on Security Boulevard.
CVE-2024-37283 | Elastic Agent up to 8.14.x elastic-agent.yml log file
CVE-2024-7557 | Red Hat OpenShift AI/OpenShift Data Science access control
CVE-2024-5445 | N-able Ecosystem Agent prior 4.5.1.2597/5.1.4.2473 certificate validation
CVE-2024-0115 | NVIDIA CV-CUDA 0.1.x - v0.9.x on Ubuntu Python API resource consumption
CVE-2024-38200 | Microsoft Office/365 Apps for Enterprise information disclosure
CVE-2024-38218 | Microsoft Edge up to 127.0.2651.74 HTML memory corruption
CVE-2024-38219 | Microsoft Edge up to 127.0.2651.74 Remote Code Execution
Confusion Attacks in Apache HTTP Server Let Attackers Gain Root Access Remotely
A recent research presentation at Black Hat USA 2024 revealed architectural vulnerabilities within the Apache HTTP Server, a widely used web server software. The research highlights several technical debts within Httpd, including three types of Confusion Attacks, nine new vulnerabilities, 20 exploitation techniques, and over 30 case studies. Apache HTTP Server operates through a modular […]
The post Confusion Attacks in Apache HTTP Server Let Attackers Gain Root Access Remotely appeared first on Cyber Security News.