ZDI-24-077: Trend Micro Apex Central Unrestricted File Upload Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The...
ZDI-24-078: Trend Micro Mobile Security for Enterprises DevicesManagementEditNotePopupTip Cross-Site Scripting Vulnerability
This vulnerability allows remote attackers to execute web requests with the victim's privileges on affected installations of Trend Micro Mobile Security for Enterprises. User interaction...
ZDI-24-079: Trend Micro Mobile Security for Enterprises ServerUpdate_UpdateSuccessful Cross-Site Scripting Vulnerability
This vulnerability allows remote attackers to execute web requests with the victim's privileges on affected installations of Trend Micro Mobile Security for Enterprises. User interaction...
ZDI-24-080: Trend Micro Mobile Security for Enterprises vpplist_assign_list Cross-Site Scripting Vulnerability
This vulnerability allows remote attackers to execute web requests with the victim's privileges on affected installations of Trend Micro Mobile Security for Enterprises. User interaction...
ansible-core-2.14.11-2.fc38
FEDORA-2024-cfa5a5cbac Packages in this update: ansible-core-2.14.11-2.fc38 Update description: Mitigate CVE-2024-0690 Read More
ansible-core-2.16.2-2.fc39
FEDORA-2024-0d894565a0 Packages in this update: ansible-core-2.16.2-2.fc39 Update description: Mitigate CVE-2024-0690 Read More
Ivanti Connect Secure and Policy Secure Gateways Zero-day Vulnerabilities (CVE-2023-46805 and CVE-2024-21887)
What is the Vulnerability? Ivanti recently published an advisory on two vulnerabilities on Jan 10, 2024 affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure...
Re: ODR violation in Redis Raft
Posted by Jeffrey Walton on Jan 18 I fail to see how a One Definition Rule (ODR) violation results in a Remote Code Execution. Can...
Minor firefox DoS – semi silently polluting ~/Downloads with files (part 2)
Posted by Georgi Guninski on Jan 18 Minor firefox DoS - semi silently polluting ~/Downloads with files (part 2) Tested on: firefox 121 and chrome...
USN-6590-1: Xerces-C++ vulnerabilities
It was discovered that Xerces-C++ was not properly handling memory management operations when parsing XML data containing external DTDs, which could trigger a use-after-free error....