Juraj Somorovsky, Marcel Maehren, Nurullah Erinola, and Robert Merget
discovered that the DTLS implementation in the JSSE subsystem of OpenJDK
did not properly restrict handshake initiation requests from clients. A
remote attacker could possibly use this to cause a denial of service.
(CVE-2023-21835)
Markus Loewe discovered that the Java Sound subsystem in OpenJDK did not
properly validate the origin of a Soundbank. An attacker could use this to
specially craft an untrusted Java application or applet that could load a
Soundbank from an attacker controlled remote URL. (CVE-2023-21843)
More Stories
USN-7360-1: Alpine vulnerabilities
It was discovered that Alpine did not use a secure connection under certain circumstances. A remote attacker could possibly use...
Drupal core – Moderately critical – Cross Site Scripting – SA-CORE-2025-004
Project: Drupal core Date: 2025-March-19 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Cross Site Scripting Affected versions: >= 8.0.0 <...
moby-engine-28.0.2-1.fc43
FEDORA-2025-728b8010fa Packages in this update: moby-engine-28.0.2-1.fc43 Update description: Automatic update for moby-engine-28.0.2-1.fc43. Changelog * Wed Mar 19 2025 Bradley G...
webkitgtk-2.48.0-1.fc42
FEDORA-2025-80e387cc51 Packages in this update: webkitgtk-2.48.0-1.fc42 Update description: Update to 2.48.0 Notably fixes CVE-2025-24201 Read More
webkitgtk-2.48.0-1.fc41
FEDORA-2025-b92313b6f2 Packages in this update: webkitgtk-2.48.0-1.fc41 Update description: Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with...
webkitgtk-2.48.0-1.fc40
FEDORA-2025-0c6c204dae Packages in this update: webkitgtk-2.48.0-1.fc40 Update description: Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with...