Open Source Vulnerabilities
Uncaught Exception (due to a data race) leads to process termination in Waitress
Uncaught Exception (due to a data race) leads to process termination in Waitress
Authentication bypass in Vartalap chat-server
Use of Incorrect Operator in polonel/trudesk
Execution with Unnecessary Privileges in polonel/trudesk
Improper Removal of Sensitive Information Before Storage or Transfer in polonel/trudesk
Improper Removal of Sensitive Information Before Storage or Transfer in polonel/trudesk
sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip
sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip
sofia-sip, sofia-sip, sofia-sip
sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip
sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip
sofia-sip, sofia-sip, sofia-sip
sofia-sip, sofia-sip, sofia-sip, sofia-sip
sofia-sip, sofia-sip, sofia-sip, sofia-sip
Integer Overflow in Vapor's HTTP Range Request
TiDB authentication bypass vulnerability
Privilege escalation from administrator in eLabFTW
sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip
sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip/ sofia-sip
sofia-sip, sofia-sip, sofia-sip
sofia-sip, sofia-sip, sofia-sip, sofia-sip
From the original tweet: Interesting maldoc was submitted from Belarus. It uses Word's external link to load the HTML and then uses the "ms-msdt" scheme to execute PowerShell code. From Microsoft: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. This issue has been nicknamed "Follina "
From the original tweet: Interesting maldoc was submitted from Belarus. It uses Word's external link to load the HTML and then uses the "ms-msdt" scheme to execute PowerShell code. From Microsoft: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. This issue has been nicknamed "Follina "
libdxfrw, librecad, libdxfrw, librecad
Security update for librecad
libdxfrw/ librecad/ libdxfrw/ librecad
Security update for librecad
Cross-site Scripting in Filter Stream Converter Application in XWiki Platform
Cross-site Scripting in Filter Stream Converter Application in XWiki Platform
Weak private key generation in SSH.NET
Improper input-size validation on the user new session name in Nextcloud Server
Improper input-size validation on the user new session name in Nextcloud Server
No verification of commits origin in github-action-merge-dependabot
No verification of commits origin in github-action-merge-dependabot
fribidi, fribidi, fribidi
Security update for fribidi
libssl-dev, libssl-doc, libssl1.0.0, openssl
Fix CVE(s): CVE-2022-1473, CVE-2022-1292
libssl-dev/ libssl-doc/ libssl1.0.0/ openssl
Fix CVE(s): CVE-2022-1473, CVE-2022-1292
platform-python, platform-python-debug, platform-python-devel, python3-devel, python3-idle, python3-libs, python3-test, python3-tkinter
Fixed CVEs in python3: CVE-2022-0391, CVE-2021-4189, CVE-2021-3737
platform-python/ platform-python-debug/ platform-python-devel/ python3-devel/ python3-idle/ python3-libs/ python3-test/ python3-tkinter
Fixed CVEs in python3: CVE-2022-0391, CVE-2021-4189, CVE-2021-3737
CureKit - Path Traversal in isFileOutsideDir
CVE-2022-1942 does not affect BellSoft software
tika, tika, tika, tika, tika, tika, tika
Missing fix for CVE-2022-30126 in 1.28.2
postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13
Security update for postgresql13
postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13/ postgresql13
Security update for postgresql13
postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12
Security update for postgresql12
postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12/ postgresql12
Security update for postgresql12
bind, bind, bind, bind, bind, bind, bind
Security update for bind
bind/ bind/ bind/ bind/ bind/ bind/ bind
Security update for bind
php74, php74
Security update for php74
dpdk, dpdk-thunderx, dpdk, dpdk-thunderx, dpdk, dpdk-thunderx
Security update for dpdk
dpdk/ dpdk-thunderx/ dpdk/ dpdk-thunderx/ dpdk/ dpdk-thunderx
Security update for dpdk
librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp
Security update for librelp
librelp/ librelp/ librelp/ librelp/ librelp/ librelp/ librelp/ librelp/ librelp/ librelp/ librelp/ librelp/ librelp
Security update for librelp
postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10
Security update for postgresql10
postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10/ postgresql10
Security update for postgresql10
