APPLE-SA-10-10-2023-1 iOS 16.7.1 and iPadOS 16.7.1
Posted by Apple Product Security via Fulldisclosure on Oct 16 APPLE-SA-10-10-2023-1 iOS 16.7.1 and iPadOS 16.7.1 iOS 16.7.1 and iPadOS 16.7.1 addresses the following issues....
XNSoft Nconvert 7.136 – Multiple Vulnerabilities
Posted by michele on Oct 16 XNSoft Nconvert 7.136 - Multiple Vulnerabilities ============================================================================ === Identifiers ------------------------------------------------- 1. CVE-2023-43250 2. CVE-2023-43251 3. CVE-2023-43252 CVSSv3.1 score -------------------------------------------------...
Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
Posted by Joshua Rogers on Oct 16 Dear fulldisclosure, Two and a half years ago an independent audit was performed on The Squid Caching Proxy,...
CVE-2022-22380
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957. Read...
CVE-2022-22375
IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request....
CVE-2021-38859
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used...
CVE-2021-29913
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM...
CVE-2021-20581
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324. Read More
CVE-2022-22384
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID:...
CVE-2022-22377
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport...