FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayVulnerabilities

Gentoo Linux Security Advisory 202310-11

Gentoo Linux Security Advisory 202310-11 - A filtering bypass in less may allow denial of service. Versions greater than or equal to 608-r2 are affected.
  • October 10th 2023 at 14:51

Ubuntu Security Notice USN-6424-1

Ubuntu Security Notice 6424-1 - It was discovered that kramdown did not restrict Rouge formatters to the correct namespace. An attacker could use this issue to cause kramdown to execute arbitrary code.
  • October 10th 2023 at 14:51

Ubuntu Security Notice USN-6423-1

Ubuntu Security Notice 6423-1 - It was discovered that CUE incorrectly handled certain files. An attacker could possibly use this issue to expose sensitive information or execute arbitrary code.
  • October 10th 2023 at 14:49

Gentoo Linux Security Advisory 202310-10

Gentoo Linux Security Advisory 202310-10 - A vulnerability has been discovered in libcue which could allow for arbitrary code execution. Versions greater than or equal to 2.2.1-r1 are affected.
  • October 10th 2023 at 14:49

Red Hat Security Advisory 2023-5527-01

Red Hat Security Advisory 2023-5527-01 - The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly. Issues addressed include a denial of service vulnerability.
  • October 10th 2023 at 14:47

Red Hat Security Advisory 2023-5538-01

Red Hat Security Advisory 2023-5538-01 - The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Issues addressed include a buffer overflow vulnerability.
  • October 10th 2023 at 14:47

Ubuntu Security Notice USN-6422-1

Ubuntu Security Notice 6422-1 - It was discovered that Ring incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code. It was discovered that Ring incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
  • October 10th 2023 at 14:47

Red Hat Security Advisory 2023-5539-01

Red Hat Security Advisory 2023-5539-01 - The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Issues addressed include a buffer overflow vulnerability.
  • October 10th 2023 at 14:46

Red Hat Security Advisory 2023-5534-01

Red Hat Security Advisory 2023-5534-01 - The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Issues addressed include a buffer overflow vulnerability.
  • October 10th 2023 at 14:44

Red Hat Security Advisory 2023-5537-01

Red Hat Security Advisory 2023-5537-01 - The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Issues addressed include a buffer overflow vulnerability.
  • October 10th 2023 at 14:16

Red Hat Security Advisory 2023-5529-01

Red Hat Security Advisory 2023-5529-01 - The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly. Issues addressed include a denial of service vulnerability.
  • October 10th 2023 at 14:16

Red Hat Security Advisory 2023-5536-01

Red Hat Security Advisory 2023-5536-01 - The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Issues addressed include a buffer overflow vulnerability.
  • October 10th 2023 at 14:14

Red Hat Security Advisory 2023-5533-01

Red Hat Security Advisory 2023-5533-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The package has been upgraded to a later upstream version: nodejs. Issues addressed include HTTP request smuggling, buffer overflow, bypass, crlf injection, and denial of service vulnerabilities.
  • October 10th 2023 at 14:12

Red Hat Security Advisory 2023-5540-01

Red Hat Security Advisory 2023-5540-01 - The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Issues addressed include a buffer overflow vulnerability.
  • October 10th 2023 at 14:09

Red Hat Security Advisory 2023-5526-01

Red Hat Security Advisory 2023-5526-01 - The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly. Issues addressed include a denial of service vulnerability.
  • October 10th 2023 at 14:06

Red Hat Security Advisory 2023-5528-01

Red Hat Security Advisory 2023-5528-01 - Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Issues addressed include a bypass vulnerability.
  • October 10th 2023 at 14:06

Red Hat Security Advisory 2023-5535-01

Red Hat Security Advisory 2023-5535-01 - The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Issues addressed include a buffer overflow vulnerability.
  • October 10th 2023 at 14:01

Red Hat Security Advisory 2023-5532-01

Red Hat Security Advisory 2023-5532-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include a bypass vulnerability.
  • October 10th 2023 at 14:01

Red Hat Security Advisory 2023-5531-01

Red Hat Security Advisory 2023-5531-01 - Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Issues addressed include a bypass vulnerability.
  • October 10th 2023 at 13:49

Gentoo Linux Security Advisory 202310-09

Gentoo Linux Security Advisory 202310-9 - Multiple vulnerabilities have been discovered in c-ares the worst of which could result in Denial of Service. Versions greater than or equal to 1.19.1 are affected.
  • October 9th 2023 at 14:26

Ubuntu Security Notice USN-6421-1

Ubuntu Security Notice 6421-1 - It was discovered that Bind incorrectly handled certain control channel messages. A remote attacker with access to the control channel could possibly use this issue to cause Bind to crash, resulting in a denial of service.
  • October 9th 2023 at 14:26

Ubuntu Security Notice USN-6420-1

Ubuntu Security Notice 6420-1 - It was discovered that Vim incorrectly handled memory when opening certain files. If an attacker could trick a user into opening a specially crafted file, it could cause Vim to crash, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. It was discovered that Vim incorrectly handled memory when opening certain files. If an attacker could trick a user into opening a specially crafted file, it could cause Vim to crash, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
  • October 9th 2023 at 14:26

Gentoo Linux Security Advisory 202310-06

Gentoo Linux Security Advisory 202310-6 - Multiple vulnerabilities have been discovered in Heimdal, the worst of which could lead to remote code execution on a KDC. Versions greater than or equal to 7.8.0-r1 are affected.
  • October 9th 2023 at 14:25

Gentoo Linux Security Advisory 202310-07

Gentoo Linux Security Advisory 202310-7 - Multiple vulnerabilities have been discovered in VirtualBox, leading to compromise of VirtualBox. Versions greater than or equal to 7.0.6 are affected.
  • October 9th 2023 at 14:25

Gentoo Linux Security Advisory 202310-08

Gentoo Linux Security Advisory 202310-8 - A root privilege escalation through setuid executable and cron job has been discovered in man-db. Versions greater than or equal to 2.8.5 are affected.
  • October 9th 2023 at 14:25

[remote] Atcom 2.7.x.x - Authenticated Command Injection

Atcom 2.7.x.x - Authenticated Command Injection
  • October 9th 2023 at 00:00

[webapps] Shuttle-Booking-Software v1.0 - Multiple-SQLi

Shuttle-Booking-Software v1.0 - Multiple-SQLi
  • October 9th 2023 at 00:00

[webapps] Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation

Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
  • October 9th 2023 at 00:00

[webapps] GLPI GZIP(Py3) 9.4.5 - RCE

GLPI GZIP(Py3) 9.4.5 - RCE
  • October 9th 2023 at 00:00

[webapps] Wordpress Sonaar Music Plugin 4.7 - Stored XSS

Wordpress Sonaar Music Plugin 4.7 - Stored XSS
  • October 9th 2023 at 00:00

[webapps] Limo Booking Software v1.0 - CORS

Limo Booking Software v1.0 - CORS
  • October 9th 2023 at 00:00

[dos] OpenPLC WebServer 3 - Denial of Service

OpenPLC WebServer 3 - Denial of Service
  • October 9th 2023 at 00:00

[webapps] Clcknshop 1.0.0 - SQL Injection

Clcknshop 1.0.0 - SQL Injection
  • October 9th 2023 at 00:00

[dos] Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service

Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service
  • October 9th 2023 at 00:00

[webapps] WEBIGniter v28.7.23 File Upload - Remote Code Execution

WEBIGniter v28.7.23 File Upload - Remote Code Execution
  • October 9th 2023 at 00:00

[webapps] Online ID Generator 1.0 - Remote Code Execution (RCE)

Online ID Generator 1.0 - Remote Code Execution (RCE)
  • October 9th 2023 at 00:00

[webapps] Webedition CMS v2.9.8.8 - Blind SSRF

Webedition CMS v2.9.8.8 - Blind SSRF
  • October 9th 2023 at 00:00

[webapps] Cacti 1.2.24 - Authenticated command injection when using SNMP options

Cacti 1.2.24 - Authenticated command injection when using SNMP options
  • October 9th 2023 at 00:00

[webapps] Splunk 9.0.5 - admin account take over

Splunk 9.0.5 - admin account take over
  • October 9th 2023 at 00:00

[remote] Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)

Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE)
  • October 9th 2023 at 00:00

[webapps] Media Library Assistant Wordpress Plugin - RCE and LFI

Media Library Assistant Wordpress Plugin - RCE and LFI
  • October 9th 2023 at 00:00

[local] Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)

Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)
  • October 9th 2023 at 00:00

[remote] Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction

Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction
  • October 9th 2023 at 00:00

[webapps] BoidCMS v2.0.0 - authenticated file upload vulnerability

BoidCMS v2.0.0 - authenticated file upload vulnerability
  • October 9th 2023 at 00:00

[remote] Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change

Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change
  • October 9th 2023 at 00:00

[webapps] Coppermine Gallery 1.6.25 - RCE

Coppermine Gallery 1.6.25 - RCE
  • October 9th 2023 at 00:00

[webapps] Minio 2022-07-29T19-40-48Z - Path traversal

Minio 2022-07-29T19-40-48Z - Path traversal
  • October 9th 2023 at 00:00

Red Hat Security Advisory 2023-5485-01

Red Hat Security Advisory 2023-5485-01 - Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.13 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.12 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.13 Release Notes for information about the most significant bug fixes and enhancements included in this release. Issues addressed include denial of service and deserialization vulnerabilities.
  • October 6th 2023 at 14:47

Red Hat Security Advisory 2023-5486-01

Red Hat Security Advisory 2023-5486-01 - Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.13 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.12 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.13 Release Notes for information about the most significant bug fixes and enhancements included in this release. Issues addressed include denial of service and deserialization vulnerabilities.
  • October 6th 2023 at 14:47

Ubuntu Security Notice USN-6416-2

Ubuntu Security Notice 6416-2 - It was discovered that the IPv6 implementation in the Linux kernel contained a high rate of hash collisions in connection lookup table. A remote attacker could use this to cause a denial of service. DaniΓ«l Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD processors utilising speculative execution and branch prediction may allow unauthorised memory reads via a speculative side-channel attack. A local attacker could use this to expose sensitive information, including kernel memory.
  • October 6th 2023 at 14:47

Apple Security Advisory 2023-10-04-1

Apple Security Advisory 2023-10-04-1 - iOS 17.0.3 and iPadOS 17.0.3 addresses buffer overflow and code execution vulnerabilities.
  • October 6th 2023 at 14:46

Red Hat Security Advisory 2023-5484-01

Red Hat Security Advisory 2023-5484-01 - Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.13 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.12 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.13 Release Notes for information about the most significant bug fixes and enhancements included in this release. Issues addressed include denial of service and deserialization vulnerabilities.
  • October 6th 2023 at 14:46

Red Hat Security Advisory 2023-5480-01

Red Hat Security Advisory 2023-5480-01 - Red Hat OpenShift Serverless release of OpenShift Serverless Logic. This release includes security fixes. Issues addressed include a bypass vulnerability.
  • October 6th 2023 at 14:46

Red Hat Security Advisory 2023-5488-01

Red Hat Security Advisory 2023-5488-01 - Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.13 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.12 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.13 Release Notes for information about the most significant bug fixes and enhancements included in this release. Issues addressed include denial of service and deserialization vulnerabilities.
  • October 6th 2023 at 14:46

Red Hat Security Advisory 2023-5491-01

Red Hat Security Advisory 2023-5491-01 - AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms. This release of Red Hat AMQ Broker 7.11.2 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.
  • October 6th 2023 at 14:46

Debian Security Advisory 5517-1

Debian Linux Security Advisory 5517-1 - Multiple security vulnerabilities were discovered in libx11, the X11 client-side library, which may result in denial of service or the execution of arbitrary code.
  • October 6th 2023 at 14:45

Debian Security Advisory 5518-1

Debian Linux Security Advisory 5518-1 - It was discovered that missing input sanitising in the encoding support in libvpx, a multimedia library for the VP8 and VP9 video codecs, may result in denial of service.
  • October 6th 2023 at 14:45

Red Hat Security Advisory 2023-5475-01

Red Hat Security Advisory 2023-5475-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.3.1. Issues addressed include buffer overflow, out of bounds write, and use-after-free vulnerabilities.
  • October 6th 2023 at 14:45

Red Hat Security Advisory 2023-5479-01

Red Hat Security Advisory 2023-5479-01 - Red Hat OpenShift Serverless Client kn 1.30.1 provides a CLI to interact with Red Hat OpenShift Serverless 1.30.1. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms. This release includes security and bug fixes, and enhancements. Issues addressed include a bypass vulnerability.
  • October 6th 2023 at 14:45

Red Hat Security Advisory 2023-5476-01

Red Hat Security Advisory 2023-5476-01 - The glibc packages provide the standard C libraries, POSIX thread libraries, standard math libraries, and the name service cache daemon used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Issues addressed include buffer overflow and privilege escalation vulnerabilities.
  • October 6th 2023 at 14:45
❌