unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Foxit Reader Array resetForm Use-After-Free Vulnerability
SummaryA use-after-free vulnerability exists in the way Foxit Reader handles an Array object. A sp...
2026-9-23 00:0:7 | 阅读: 0 |
收藏
|
0day Fans - talosintelligence.com
00000148
00007ff7
vsnprintf
00000045
Apple macOS CoreWLAN information disclosure vulnerability
SummaryA information disclosure vulnerability exists in the CoreWLAN functionality of macOS (versi...
2026-9-23 00:0:7 | 阅读: 0 |
收藏
|
0day Fans - talosintelligence.com
bssid
ssid
2026
network
bssidlist
Microsoft Windows Cloud Files Mini Filter Driver CldiStreamPrepareRequestForMoreProcessing Type Confusion vulnerability
SummaryA type confusion vulnerability exists in the CldiStreamPrepareRequestForMoreProcessing func...
2026-9-8 23:59:3 | 阅读: 18 |
收藏
|
0day Fans - talosintelligence.com
ffffc60a
cldflt
fffff806
ffff918f
hypervisor
Adobe Photoshop Installation privilege escalation vulnerability
SummaryA privilege escalation vulnerability exists in the Installation functionality of Photoshop...
2026-8-26 00:0:11 | 阅读: 10 |
收藏
|
0day Fans - talosintelligence.com
photoshop
winget
jnjpo4r
571
Microsoft Windows TCPIP.SYS IppQualifyAddresses Out-of-Bounds Read Vulnerability
SummaryAn out-of-bounds read vulnerability exists in the IppQualifyAddresses function of the Micro...
2026-8-11 23:59:7 | 阅读: 22 |
收藏
|
0day Fans - talosintelligence.com
tcpip
hypervisor
ffffce0b
fffff807
Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteRequest use-after-free vulnerability
SummaryA use-after-free vulnerability exists in the CldiStreamCompleteRequest functionality of Win...
2026-7-17 00:0:35 | 阅读: 23 |
收藏
|
0day Fans - talosintelligence.com
cldflt
hypervisor
ffffc80b
fffff801
ffffa685
Microsoft Windows NETIO.sys NsipGetAllInformationProviderParameters Information Disclosure Vulnerability
SummaryAn out-of-bounds pointer offset vulnerability exists in the NsipGetAllInformationProviderPa...
2026-7-16 00:0:59 | 阅读: 17 |
收藏
|
0day Fans - talosintelligence.com
fffff807
netio
keybuffer
Foxit Foxit Reader Javascript checkbox CBF_Widget code execution vulnerability
SummaryA code execution vulnerability exists in the Javascript checkbox CBF_Widget functionality o...
2026-7-8 23:59:22 | 阅读: 17 |
收藏
|
0day Fans - talosintelligence.com
00000232
00007ff6
vsnprintf
foxit
WolfSSL wolfSSL X.509 registeredID name constraints enforcement improper input validation vulnerability
SummaryA improper input validation vulnerability exists in the X.509 registeredID name constraints...
2026-7-1 23:59:55 | 阅读: 15 |
收藏
|
0day Fans - talosintelligence.com
wolfssl
rid
2026
generalname
WolfSSL wolfSSL X.509 iPAddress name constraints enforcement improper input validation vulnerability
SummaryA improper input validation vulnerability exists in the X.509 iPAddress name constraints en...
2026-7-1 00:0:19 | 阅读: 19 |
收藏
|
0day Fans - talosintelligence.com
wolfssl
altnames
permitted
2026
ipaddress
WolfSSL wolfSSL PKCS#7 OtherRecipientInfo integer underflow vulnerability
SummaryA integer underflow vulnerability exists in the PKCS#7 OtherRecipientInfo functionality of...
2026-7-1 00:0:19 | 阅读: 15 |
收藏
|
0day Fans - talosintelligence.com
pkcs7
word32
wolfssl
pkimsg
orivaluesz
vtk vtk-dicom vtkDICOMItem::FindDataElementOrInsert heap-based buffer overflow vulnerability
SummaryA heap-based buffer overflow vulnerability exists in the vtkDICOMItem::FindDataElementOrIns...
2026-6-25 00:0:29 | 阅读: 13 |
收藏
|
0day Fans - talosintelligence.com
vtk
pthread
tptr
cxx
Tp-Link Archer AX53 v1.0 Openvpn configuration restore client_connect OS command injection vulnerability
SUMMARYAn os command injection vulnerability exists in the Openvpn configuration restore client_co...
2026-5-7 00:0:4 | 阅读: 22 |
收藏
|
0day Fans - talosintelligence.com
openvpn
client
remote
ifconfig
persist
Tp-Link Archer AX53 v1.0 Openvpn configuration restore script_security OS command injection vulnerability
SUMMARYAn os command injection vulnerability exists in the Openvpn configuration restore script_se...
2026-5-7 00:0:4 | 阅读: 20 |
收藏
|
0day Fans - talosintelligence.com
openvpn
client
remote
ifconfig
backup
Tp-Link Archer AX53 v1.0 dnsmasq configuration restore TFTP server enable vulnerability
SUMMARYAn external config control vulnerability exists in the Openvpn configuration restore route_...
2026-5-7 00:0:4 | 阅读: 22 |
收藏
|
0day Fans - talosintelligence.com
tftp
archer
ax53
dnsmasq
readethers
Norton Secure VPN Installation Insecure Operation On Junction Privilege Escalation Vulnerability
SUMMARYA privilege escalation vulnerability exists during the installation of Norton Secure VPN vi...
2026-5-3 23:59:3 | 阅读: 17 |
收藏
|
0day Fans - talosintelligence.com
057cd4cd
413f
d429
OpenVPN TLS Crypt v2 Client Key Extraction denial of service vulnerability
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内,而且不需要特定的开头。首先,我得仔细阅读文章,理解其主要内容。 文章主要讲的是OpenVPN 2.6.x和2.8_git版本中的一个漏洞。这个漏洞是在TLS Crypt v2客户端密钥提取功能中发现的,攻击者可以通过发送特定的网络包导致服务拒绝(DoS)。漏洞的CVSS评分是7.7,属于中等偏高风险。 接下来,我需要提取关键点:漏洞名称、影响版本、攻击方式、后果以及修复情况。然后将这些信息浓缩到100字以内,确保语言简洁明了。 可能会遇到的问题是如何在有限的字数内涵盖所有重要信息。我需要优先选择最重要的内容,比如漏洞的存在、影响范围、攻击效果和修复建议。 最后,检查字数是否符合要求,并确保没有使用任何不需要的开头语句。 </think> OpenVPN 2.6.x和2.8_git版本中存在一个可利用的断言漏洞,可能导致服务拒绝。攻击者通过发送恶意网络包触发此漏洞,导致服务器崩溃。该漏洞已修复,建议用户更新至最新版本以避免风险。...
2026-4-26 23:59:37 | 阅读: 18 |
收藏
|
0day Fans - talosintelligence.com
crypt
client
openvpn
wkc
2026
Adobe Photoshop Installation Privilege Escalation Vulnerability
好的,我需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读全文,抓住关键点。文章讲的是Adobe Photoshop通过微软商店安装时存在一个权限提升漏洞。 漏洞出现在安装程序Photoshop_Set-Up.exe版本2.11.0.30中。低权限用户可以在安装过程中替换文件,导致权限被意外提升。CVSSv3评分为8.2,属于高危漏洞。 接下来,我需要把这些信息浓缩成一句话,确保不超过100字。要包含软件名称、漏洞类型、影响以及评分。这样用户就能快速了解主要内容了。 </think> Adobe Photoshop通过微软商店安装时存在权限提升漏洞,低权限用户可替换安装文件以获取高权限,CVSSv3评分为8.2。...
2026-4-21 23:59:24 | 阅读: 20 |
收藏
|
0day Fans - talosintelligence.com
photoshop
privileges
attacker
talos
2026
LibRaw uncompressed_fp_dng_load_raw integer overflow vulnerability
嗯,用户让我用中文总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述。好的,我先看看文章讲的是什么。 文章主要讲的是LibRaw库中的一个整数溢出漏洞。具体来说,在uncompressed_fp_dng_load_raw函数中,由于使用了32位算术运算,导致堆缓冲区溢出。攻击者可以通过构造恶意文件来触发这个漏洞。 接下来,我需要提取关键信息:漏洞存在于哪个版本?LibRaw的Commit 8dc68e2。漏洞类型是CWE-190,CVSSv3评分是8.1。影响方面,当max_raw_memory_mb设置超过约16GB时,应用会变得易受攻击。 现在我要把这些信息浓缩到100字以内。确保涵盖漏洞名称、位置、影响和触发条件。 可能的结构:LibRaw特定版本中的整数溢出导致堆缓冲区溢出;攻击者利用恶意DNG文件触发;当内存限制超过约16GB时易受攻击。 这样应该能简洁明了地传达主要内容。 </think> LibRaw特定版本中存在整数溢出漏洞,导致堆缓冲区溢出。攻击者可构造恶意DNG文件触发该漏洞。当内存限制超过约16GB时,应用易受攻击。...
2026-4-7 00:0:55 | 阅读: 25 |
收藏
|
0day Fans - talosintelligence.com
tiles
libraw
overflow
tilewidth
dng
LibRaw HuffTable::initval heap-based buffer overflow vulnerability
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要仔细阅读这篇文章,了解它的主要信息。 文章讲的是LibRaw库中的一个堆溢出漏洞,具体是在HuffTable::initval函数里。这个漏洞是因为处理Huffman表时没有正确计算缓冲区的大小。攻击者可以通过构造恶意文件来触发这个漏洞,导致堆溢出。 接下来,我需要提取关键信息:漏洞类型是堆溢出,影响的是LibRaw的特定提交版本,CVSS评分很高,达到了9.8分。此外,漏洞是由于未验证输入导致的缓冲区大小计算错误。 现在我要把这些信息浓缩到100字以内。首先点明漏洞类型和位置,然后说明影响的版本和评分,最后提到问题原因。这样就能全面而简洁地总结文章内容了。 </think> LibRaw的HuffTable::initval函数存在堆溢出漏洞,因未验证输入导致缓冲区大小计算错误。攻击者可利用恶意文件触发该漏洞。...
2026-4-7 00:0:55 | 阅读: 33 |
收藏
|
0day Fans - talosintelligence.com
nbits
libraw
hufftable
huffman
Previous
0
1
2
3
4
5
6
7
Next