This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric APC Easy UPS Online. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Daily Archives: June 11, 2024
ZDI-24-599: Adobe Substance 3D Stager SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Substance 3D Stager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-34115.
ZDI-24-598: (0Day) Microsoft Windows Incorrect Permission Assignment Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Furthermore, the vulnerable behavior occurs only in certain hardware configurations. The ZDI has assigned a CVSS rating of 7.7.
USN-6827-1: LibTIFF vulnerability
It was discovered that LibTIFF incorrectly handled memory when
performing certain cropping operations, leading to a heap buffer
overflow. An attacker could use this issue to cause a
denial of service, or possibly execute arbitrary code.
DSA-5707-1 vlc – security update
A buffer overflow was discovered in the MMS module of the VLC media
player.
DSA-5708-1 cyrus-imapd – security update
Damian Poddebniak discovered that the Cyrus IMAP server didn’t restrict
memory allocation for some command arguments which may result in denial
of service. This update backports new config directives which allow to
configure limits, additional details can be found at:
https://www.cyrusimap.org/3.6/imap/download/release-notes/3.6/x/3.6.5.html
These changes are too intrusive to be backported to the version of
Cyrus in the oldstable distribution (bullseye). If the IMAP server is used
by untrusted users an update to Debian stable/bookworm is recommended.
In addition the version of cyrus-imapd in bullseye-backports will be
updated with a patch soon.