ZDI-23-890: (Pwn2Own) Microsoft Windows UMPDDrvEnablePDEV Improper Input Validation Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code...
ZDI-23-880: Microsoft Azure Machine Learning Service DSIMountAgent Missing Authentication Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on Microsoft Azure. An attacker must first obtain the ability to execute low-privileged code on the...
libX11-1.8.6-1.fc38
FEDORA-2023-7503ce855c Packages in this update: libX11-1.8.6-1.fc38 Update description: libX11 1.8.6 (CVE-2023-3138) Read More
DSA-5430 openjdk-17 – security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions. Read...
DSA-5431 sofia-sip – security update
Xu Biang discovered that missing input sanitising in Sofia-SIP, a SIP User-Agent library could result in denial of service. Read More
dotnet7.0-7.0.107-1.fc37
FEDORA-2023-e6d5cb11bb Packages in this update: dotnet7.0-7.0.107-1.fc37 Update description: This is the June 2023 monthly update for .NET 7. It includes fixes for several CVEs. Release...
dotnet7.0-7.0.107-1.fc38
FEDORA-2023-ee819d655b Packages in this update: dotnet7.0-7.0.107-1.fc38 Update description: This is the June 2023 monthly update for .NET 7. It includes fixes for several CVEs. Release...
dotnet6.0-6.0.118-1.fc37
FEDORA-2023-edb993aeaf Packages in this update: dotnet6.0-6.0.118-1.fc37 Update description: This is the June 2023 monthly update for .NET 6. It includes fixes for several CVEs. Release...
dotnet6.0-6.0.118-1.fc38
FEDORA-2023-401e38c388 Packages in this update: dotnet6.0-6.0.118-1.fc38 Update description: This is the June 2023 monthly update for .NET 6. It includes fixes for several CVEs. Release...
USN-6169-1: GNU SASL vulnerability
It was discovered that GNU SASL's GSSAPI server could make an out-of-bounds reads if given specially crafted GSS-API authentication data. A remote attacker could possibly...