CPP-Ethereum JSON-RPC miner_setEtherbase improper authorization Vulnerability

### Summary An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum’s JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can c ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Nimbus JOSE+JWT vulnerable to padding oracle attack

Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.Read More ...

Continue Reading

CVSS3 - LOW

CVSS2 - MEDIUM

Apache Tomcat Request Obfuscation Vulnerability

Apache Tomcat is a lightweight Web application server from the Apache Foundation. The application implements support for Servlet and JavaServer Page (JSP).Apache Tomcat suffers from a request obfuscat ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which a ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

July 7th 2022 Security Releases

# July 7th 2022 Security Releases By Rafael Gonzaga, 2022-07-07 ## _(Update 07-July-2022)_ Security releases available Updates are now available for the v18.x, v16.x, and v14.x Node.js release lines f ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Critical: java-1.7.0-openjdk

**Issue Overview:** It was discovered that the DCG implementation in the RMI component of OpenJDK failed to correctly handle references. A remote attacker could possibly use this flaw to execute arbit ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

A newline character causes the Oscar vulnerability 0day(CVE-2017-8759)reproduction-latest Office the highest level of threat attack warning-vulnerability warning-the black bar safety net

Krzysztof, the 360 group focus of the Security Business Unit elucidating the team invented a new type of Office document high-end intimidating onslaught, the 进击应用了9月12æ� ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Microsoft Windows .NET Framework – Remote Code Execution

Post ContentRead More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: