USN-6377-1: LibRaw vulnerability
It was discovered that LibRaw incorrectly handled certain photo files. If a user o automated system were tricked into processing a specially crafted photo file,...
USN-6376-1: c-ares vulnerability
It was discovered that c-ares incorrectly parsed certain SOA replies. A remote attacker could possibly use this issue to cause c-res to crash, resulting in...
Using Hacked LastPass Keys to Steal Cryptocurrency
Remember last November, when hackers broke into the network for LastPass—a password database—and stole password vaults with both encrypted and plaintext data for over 25...
SEC Consult SA-20230918-0 :: Authenticated Remote Code Execution and Missing Authentication in Atos Unify OpenScape
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Sep 18 SEC Consult Vulnerability Lab Security Advisory < 20230918-0 > ======================================================================= title: Authenticated Remote...
SEC Consult SA-20230829-0 :: Reflected Cross-Site Scripting (XSS) in PTC – Codebeamer (ALM Solution)
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Sep 18 SEC Consult Vulnerability Lab Security Advisory < 20230829-0 > ======================================================================= title: Reflected Cross-Site...
APPLE-SA-2023-09-11-3 macOS Big Sur 11.7.10
Posted by Apple Product Security via Fulldisclosure on Sep 18 APPLE-SA-2023-09-11-3 macOS Big Sur 11.7.10 macOS Big Sur 11.7.10 addresses the following issues. Information about...
APPLE-SA-2023-09-11-2 macOS Monterey 12.6.9
Posted by Apple Product Security via Fulldisclosure on Sep 18 APPLE-SA-2023-09-11-2 macOS Monterey 12.6.9 macOS Monterey 12.6.9 addresses the following issues. Information about the security...
APPLE-SA-2023-09-11-1 iOS 15.7.9 and iPadOS 15.7.9
Posted by Apple Product Security via Fulldisclosure on Sep 18 APPLE-SA-2023-09-11-1 iOS 15.7.9 and iPadOS 15.7.9 iOS 15.7.9 and iPadOS 15.7.9 addresses the following issues....
[SYSS-2023-002] Razer Synapse – Local Privilege Escalation
Posted by Oliver Schwarz via Fulldisclosure on Sep 18 Advisory ID: SYSS-2023-002 Product: Razer Synapse Manufacturer: Razer Inc. Affected Version(s): Versions before 3.8.0428.042117 (20230601) Tested...
roundcubemail-1.5.4-1.el9
FEDORA-EPEL-2023-c5aefc68ee Packages in this update: roundcubemail-1.5.4-1.el9 Update description: Version 1.5.4 Fix cross-site scripting (XSS) vulnerability in handling of linkrefs in plain text messages Fix so...