Lucene search

K

CFR-4EAB, CFR-8EAB, CFR-16EAB Security Vulnerabilities

attackerkb
attackerkb

CVE-2024-5274

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Recent assessments: Assessed Attacker Value: 0 Assessed Attacker Value: 0Assessed Attacker Value:...

8.8CVSS

8.7AI Score

0.003EPSS

2024-05-28 12:00 AM
securelist
securelist

Message board scams

Marketplace fraud is nothing new. Cybercriminals swindle money out of buyers and sellers alike. Lately, we've seen a proliferation of cybergangs operating under the Fraud-as-a-Service model and specializing in tricking users of online marketplaces, in particular, message boards. Criminals are...

6.4AI Score

2024-05-27 01:00 PM
9
github
github

How AI enhances static application security testing (SAST)

In a 2023 GitHub survey, developers reported that their top task, second only to writing code (32%), was finding and fixing security vulnerabilities (31%). As their teams "shift left" and integrate security checks earlier into the software development lifecycle (SDLC), developers have become the...

7.8AI Score

2024-05-09 04:00 PM
6
github
github

phpMyFAQ SQL Injection at "Save News"

Summary A SQL injection vulnerability has been discovered in the the "Add News" functionality due to improper escaping of the email address. This allows any authenticated user with the rights to add/edit FAQ news to exploit this vulnerability to exfiltrate data, take over accounts and in some...

8.8CVSS

8.8AI Score

0.0004EPSS

2024-03-25 07:44 PM
16
osv
osv

phpMyFAQ SQL Injection at "Save News"

Summary A SQL injection vulnerability has been discovered in the the "Add News" functionality due to improper escaping of the email address. This allows any authenticated user with the rights to add/edit FAQ news to exploit this vulnerability to exfiltrate data, take over accounts and in some...

8.8CVSS

9.1AI Score

0.0004EPSS

2024-03-25 07:44 PM
13
fedora
fedora

[SECURITY] Fedora 40 Update: CFR-0.151-16.fc40

CFR will decompile modern Java features - including much of Java 9, 12 & 14, but is written entirely in Java 6, so will work anywhere! It'll even make a decent go of turning class files from other JVM languages b ack into...

9.1AI Score

0.0004EPSS

2024-03-07 10:32 PM
3
mskb
mskb

February 13, 2024—KB5034765 (OS Builds 22621.3155 and 22631.3155)

February 13, 2024—KB5034765 (OS Builds 22621.3155 and 22631.3155) UPDATED 2/27/24 IMPORTANT: New dates for the end of non-security updates for Windows 11, version 22H2The new end date is June 24, 2025 for Windows 11, version 22H2 Enterprise, Education, IoT Enterprise, and Enterprise multi-session.....

8.8CVSS

7.7AI Score

0.014EPSS

2024-02-13 08:00 AM
32
cve
cve

CVE-2023-47674

Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,....

9.8CVSS

9.4AI Score

0.001EPSS

2023-11-16 08:15 AM
10
nvd
nvd

CVE-2023-47674

Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,....

9.8CVSS

0.001EPSS

2023-11-16 08:15 AM
cve
cve

CVE-2023-47213

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB....

9.8CVSS

9.2AI Score

0.001EPSS

2023-11-16 08:15 AM
8
nvd
nvd

CVE-2023-47213

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB....

9.8CVSS

0.001EPSS

2023-11-16 08:15 AM
2
prion
prion

Hardcoded credentials

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB....

9.8CVSS

7.1AI Score

0.001EPSS

2023-11-16 08:15 AM
5
prion
prion

Authentication flaw

Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,....

9.8CVSS

7.4AI Score

0.001EPSS

2023-11-16 08:15 AM
2
msupdate
msupdate

2023-10 .NET 7.0.13 Security Update for x64 Server (KB5032875)

2023-10 .NET 7.0.13 Security Update for x64 Server...

7.4AI Score

2023-10-24 05:00 PM
3
schneier
schneier

AI and US Election Rules

If an AI breaks the rules for you, does that count as breaking the rules? This is the essential question being taken up by the Federal Election Commission this month, and public input is needed to curtail the potential for AI to take US campaigns (even more) off the rails. At issue is whether...

6.6AI Score

2023-10-20 11:10 AM
16
wpvulndb
wpvulndb

BEAR for WordPress < 1.1.4 - Arbitrary Settings Update via CSRF

Description The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF...

4.3CVSS

6.5AI Score

0.001EPSS

2023-10-20 12:00 AM
5
zdt

8.8CVSS

7.1AI Score

0.002EPSS

2023-08-24 12:00 AM
194
packetstorm

0.002EPSS

2023-08-23 12:00 AM
115
cve
cve

CVE-2023-28541

Memory Corruption in Data Modem while processing DMA buffer release event about CFR...

7.8CVSS

7.7AI Score

0.0004EPSS

2023-07-04 05:15 AM
29
nvd
nvd

CVE-2023-28541

Memory Corruption in Data Modem while processing DMA buffer release event about CFR...

7.8CVSS

7.8AI Score

0.0004EPSS

2023-07-04 05:15 AM
prion
prion

Memory corruption

Memory Corruption in Data Modem while processing DMA buffer release event about CFR...

7.8CVSS

7.7AI Score

0.0004EPSS

2023-07-04 05:15 AM
2
mskb
mskb

.NET 6.0 Update - June 13, 2023 (KB5027797)

.NET 6.0 Update - June 13, 2023 (KB5027797) .NET 6.0 has been refreshed with the latest update as of June 13, 2023. This update contains both security and non-security fixes. See the release notes for details on updated packages..NET 6.0 servicing updates are upgrades. The latest servicing update.....

7.8CVSS

7.6AI Score

0.002EPSS

2023-06-13 07:00 AM
78
githubexploit
githubexploit

Exploit for Insecure Default Initialization of Resource in Apache Superset

CVE-2023-27524: Apache Superset Auth Bypass Script to check...

9.8CVSS

9.3AI Score

0.97EPSS

2023-05-04 01:29 PM
116
threatpost
threatpost

Ukrainian DDoS Attacks Should Put US on Notice–Researchers

On Tuesday, institutions central to Ukraine’s military and economy were hit with a wave of denial-of-service (DoS) attacks, which sparked an avalanche of headlines around the world. The strike itself had limited impact — but the larger implications for critical infrastructure beyond the Ukraine...

10CVSS

0.5AI Score

0.976EPSS

2022-02-17 04:04 PM
44
kitploit
kitploit

reFlutter - Flutter Reverse Engineering Framework

This framework helps with Flutter apps reverse engineering using the patched version of the Flutter library which is already compiled and ready for app repacking. This library has snapshot deserialization process modified to allow you perform dynamic analysis in a convenient way. Key features: ...

7.5AI Score

2022-01-17 08:30 PM
263
suse
suse

Security update for hylafax+ (moderate)

An update that contains security fixes can now be installed. Description: hylafax+ was updated to version 7.0.4: README.SUSE renamed hylafax.diff added for boo#1191571 (pre-correction) Dependencies on systemd-services adjusted retry training twice at the same bitrate unless FTT (26 Aug 2021) add...

6.9AI Score

2021-11-21 12:00 AM
17
rapid7blog
rapid7blog

Update to GLBA Security Requirements for Financial Institutions

Heads up financial institutions: the Federal Trade Commission (FTC) announced the first cybersecurity updates to the Gramm Leach-Bliley Act (GLBA) Safeguards Rule since 2003. The new rule strengthens the required security safeguards for customer information. This includes formal risk assessments,.....

6.4AI Score

2021-11-10 07:55 PM
14
kitploit
kitploit

Rtl_433 - Program To Decode Radio Transmissions From Devices On The ISM Bands (And Other Frequencies)

rtl_433 (despite the name) is a generic data receiver, mainly for the 433.92 MHz, 868 MHz (SRD), 315 MHz, 345 MHz, and 915 MHz ISM bands. The official source code is in the https://github.com/merbanan/rtl_433/ repository. For more documentation and related projects see the https://triq.org/ site......

7.5AI Score

2021-07-30 12:30 PM
723
rapid7blog
rapid7blog

Proposed security researcher protection under CFAA

Rapid7 views independent cybersecurity research and the security community as important drivers for advancing cybersecurity for all, a core value for Rapid7. One way we take action on this value is by supporting protection for security researchers acting in good faith. We have spoken out on this...

-0.2AI Score

2021-06-04 02:46 PM
28
cve
cve

CVE-2021-22853

The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to...

5.4CVSS

5.5AI Score

0.001EPSS

2021-02-17 02:15 PM
21
2
cve
cve

CVE-2021-22854

The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without...

7.5CVSS

7.7AI Score

0.002EPSS

2021-02-17 02:15 PM
22
nvd
nvd

CVE-2021-22853

The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to...

5.4CVSS

0.001EPSS

2021-02-17 02:15 PM
nvd
nvd

CVE-2021-22855

The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary...

9.8CVSS

0.009EPSS

2021-02-17 02:15 PM
1
prion
prion

Design/Logic Flaw

The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to...

5.4CVSS

5.5AI Score

0.001EPSS

2021-02-17 02:15 PM
5
cvelist
cvelist

CVE-2021-22853 Soar Cloud System Co., Ltd. HR Portal - Broken Access Control

The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to...

5.4CVSS

5.7AI Score

0.001EPSS

2021-02-17 12:00 AM
1
Total number of security vulnerabilities246