Nine arrests and millions of euros seized in bid to bust JuicyFields investment scammers
Monthly Archives: April 2024
ZDI-24-365: (Pwn2Own) Microsoft Edge DOMArrayBuffer Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2024-2886.
ZDI-24-366: (Pwn2Own) Google Chrome WASM Improper Input Validation Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2024-2887.
ZDI-24-367: (Pwn2Own) Google Chrome V8 Enum Cache Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2024-3159.
DSA-5660-1 php7.4 – security update
Multiple security issues were found in PHP, a widely-used open source
general purpose scripting language which could result in secure cookie
bypass, XXE attacks or incorrect validation of password hashes.
DSA-5661-1 php8.2 – security update
Multiple security issues were found in PHP, a widely-used open source
general purpose scripting language which could result in secure cookie
bypass, XXE attacks or incorrect validation of password hashes.
pgadmin4-7.8-5.fc39
FEDORA-2024-f04c2ec90b
Packages in this update:
pgadmin4-7.8-5.fc39
Update description:
Backport fix for CVE-2024-3116.
mingw-python-idna-3.7-1.fc40
FEDORA-2024-1230cb2cd6
Packages in this update:
mingw-python-idna-3.7-1.fc40
Update description:
Update to idna-3.7.
mingw-python-idna-3.7-1.fc39
FEDORA-2024-83ef5f3c4f
Packages in this update:
mingw-python-idna-3.7-1.fc39
Update description:
Update to idna-3.7.
mingw-python-idna-3.7-1.fc38
FEDORA-2024-831b7c8340
Packages in this update:
mingw-python-idna-3.7-1.fc38
Update description:
Update to idna-3.7.