This vulnerability allows remote attackers to execute arbitrary code on affected installations of WECON LeviStudioU. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
DSA-5085 expat – security update
Several vulnerabilities have been discovered in Expat, an XML parsing C
library, which could result in denial of service or potentially the
execution of arbitrary code, if a malformed XML file is processed.
Teen Framed for Cybercrime Files Lawsuit
Teen sues school and Meta after being arrested and detained over cyber-threats she didn’t make
Nurse and Marine Charged Over Fake Vaccination Card Scheme
Marine Corps reservist and nurse allegedly sold hundreds of forged coronavirus inoculation cards
Maryland Couple Conspired to Sell Nuclear Secrets
Nuclear engineer and wife admit plot to steal restricted data and sell it to a foreign power
FBI warns of fake CEO attacks taking place via video conferencing systems
The FBI has issued a warning that organisations should be on their guard against BEC (Business Email Compromise) attacks involving virtual meeting platforms.
Read more in my article on the Hot for Security blog.
USN-5293-1: c3p0 vulnerability
Aaron Massey discovered that c3p0 could be made to crash when
parsing certain input. An attacker able to modify the application’s
XML configuration file could cause a denial of service.
USN-5288-1: Expat vulnerabilities
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
vim-8.2.4428-1.fc34
FEDORA-2022-7ef65e6444
Packages in this update:
vim-8.2.4428-1.fc34
Update description:
Security fix for CVE-2022-0696
Security fix for CVE-2022-0629
Security fix for CVE-2022-0572
Security fixes for CVE-2022-0408, CVE-2022-0413, CVE-2022-0393, CVE-2022-0417, CVE-2022-0443
vim-8.2.4428-1.fc35
FEDORA-2022-8622ebdebb
Packages in this update:
vim-8.2.4428-1.fc35
Update description:
The newest upstream commit
Security fix for CVE-2022-0629