Open Source Vulnerabilities
Chat poll data can still be queried from API after purging history in Nextcloud talk
Chat poll data can still be queried from API after purging history in Nextcloud talk
Users can set up workflows using restricted and invisible system tags in Nextcloud
Users can set up workflows using restricted and invisible system tags in Nextcloud
org.xwiki.platform:xwiki-platform-logging-ui Injection vulnerability
org.xwiki.platform:xwiki-platform-logging-ui Injection vulnerability
Insecure header validation in slim/psr7
Improper header name validation in guzzlehttp/psr7
`chainId` may be outdated if user changes chains as part of connection in @web3-react
`chainId` may be outdated if user changes chains as part of connection in @web3-react
Path traversal vulnerability in gatsby-plugin-sharp
kernel-linus
Updated kernel-linus packages fix security vulnerability
kernel-linus
Updated kernel-linus packages fix security vulnerability
kernel, kmod-virtualbox, kmod-xtables-addons
Updated kernel packages fix security vulnerability
kernel/ kmod-virtualbox/ kmod-xtables-addons
Updated kernel packages fix security vulnerability
Path Traversal Vulnerability in hap-wi/roxy-wi
apache-superset
Apache Superset vulnerable to Improper Authorization
apache-superset
Apache Superset vulnerable to Improper Authorization
@openzeppelin/contracts, @openzeppelin/contracts-upgradeable
OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated
@openzeppelin/contracts/ @openzeppelin/contracts-upgradeable
OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated
borsh
Parsing borsh messages with ZST which are not-copy/clone is unsound
borsh
Parsing borsh messages with ZST which are not-copy/clone is unsound
Apache Superset: Possible SSRF on import datasets
Apache Superset: Incorrect default permissions for Gamma role
Apache Superset: Incorrect default permissions for Gamma role
nodejs14
Security update for nodejs14
nss, nss-devel, nss-pkcs11-devel, nss-softokn, nss-softokn-devel, nss-softokn-freebl, nss-softokn-freebl-devel, nss-sysinit, nss-tools, nss-util, nss-util-devel
nss: Fix of CVE-2023-0767
nss/ nss-devel/ nss-pkcs11-devel/ nss-softokn/ nss-softokn-devel/ nss-softokn-freebl/ nss-softokn-freebl-devel/ nss-sysinit/ nss-tools/ nss-util/ nss-util-devel
nss: Fix of CVE-2023-0767
nodejs10, nodejs10, nodejs10, nodejs10, nodejs10, nodejs10, nodejs10, nodejs10
Security update for nodejs10
nodejs10/ nodejs10/ nodejs10/ nodejs10/ nodejs10/ nodejs10/ nodejs10/ nodejs10
Security update for nodejs10
harfbuzz
Heap-buffer-overflow in OT::glyf_impl::SubsetGlyph::serialize
harfbuzz
Heap-buffer-overflow in OT::glyf_impl::SubsetGlyph::serialize
ruby
Use-after-poison in str_new_frozen_buffer
libucl
Heap-use-after-free in ucl_hash_func
nss, nss-devel, nss-pkcs11-devel, nss-softokn, nss-softokn-devel, nss-softokn-freebl, nss-softokn-freebl-devel, nss-sysinit, nss-tools, nss-util, nss-util-devel
nss: Fix of CVE-2023-0767
nss/ nss-devel/ nss-pkcs11-devel/ nss-softokn/ nss-softokn-devel/ nss-softokn-freebl/ nss-softokn-freebl-devel/ nss-sysinit/ nss-tools/ nss-util/ nss-util-devel
nss: Fix of CVE-2023-0767
rubygem-rack, rubygem-rack
Security update for rubygem-rack
rubygem-rack/ rubygem-rack
Security update for rubygem-rack
