Collected every two hours from specialised publications — each link leads to the original article.
Requests, a Python HTTP library, has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. For HTTP connections…
It was discovered that PHP's implementation of SOAP HTTP Digest authentication performed insufficient error validation, which may result in a stack information…
It was discovered that PHP's implementation of SOAP HTTP Digest authentication performed insufficient error validation, which may result in a stack information…
Cross-site scripting (XSS) vulnerabilities were found in rainloop, a web-based email client, which could lead to information disclosure including passphrase le…
EventSource could leak sensitive information if it opened a specially crafted input file.
Multiple vulnerabilities were discovered in the Go programming language. An attacker could trigger a denial-of-service (DoS), invalid cryptographic computation…
It was reported that HAProxy, a fast and reliable load balancing reverse proxy, does not properly initialize connection buffers when encoding the FCGI_BEGIN_RE…
Multiple vulnerabilities were discovered in runc, the Open Container Project runtime, which is often used with virtualization environments such as Docker. Mali…
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks.
Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, information leak, or potentially the exec…
Several vulnerabilities have been discovered in imagemagick that may lead to a privilege escalation, denial of service or information leaks. CVE-2020-19667
This update upgrades Thunderbird to version 102.8.0. * Mozilla: Arbitrary memory write via PKCS 12 in NSS (CVE-2023-0767) * Mozilla: Content security policy le…
This update upgrades Firefox to version 102.8.0 ESR. * Mozilla: Arbitrary memory write via PKCS 12 in NSS (CVE-2023-0767) * Mozilla: Content security policy le…
Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacke…
Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacke…
Jacob Champion discovered that libpq can leak memory contents after GSSAPI transport encryption initiation fails. A modified server, or an unauthenticated man-…
Multiple issues were found in Git, a distributed revision control system. An attacker may trigger remote code execution, cause local users into executing arbit…
v1.5.1 - fix logging to stdout when --stdout is used *thanks to Eta - update --treshold option accept decimal numbers as parameter - fix crashes when processin…
This update upgrades Firefox to version 102.6.0 ESR. * Mozilla: Arbitrary file read from a compromised content process (CVE-2022-46872) * Mozilla: Memory safet…
This update upgrades Thunderbird to version 102.6.0. * Mozilla: Arbitrary file read from a compromised content process (CVE-2022-46872) * Mozilla: Memory safet…
Multiple issues were found in Git, a distributed revision control system. An attacker may cause other local users into executing arbitrary commands, leak infor…
Timothee Desurmont discovered an information leak vulnerability in node-eventsource, a W3C compliant EventSource client for Node.js: the module was not honorin…
ranjit-git discovered an information leak vulnerability in node-fetch, a Node.js module exposing a window.fetch compatible API on Node.js runtime: the module w…
APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.