ZDI-22-1590: Parse Server transformUpdate Prototype Pollution Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Parse Server. Authentication is not required to exploit this vulnerability. Read More
ZDI-22-1589: Microsoft Windows Output Protection Manager Integer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code...
Somnia Ransomware Targets Ukraine
FortiGuard Labs is aware of a report that a new ransomware "Somnia" was observed in attacks against Ukraine. Somnia ransomware was deployed as a final...
Emotet Distributed Through U.S. Election Themed Link Files
FortiGuard Labs has discovered that Emotet was recently delivered through an archive file that has a file name targeting those interested in the U.S. midterm...
USN-5722-1: nginx vulnerabilities
It was discovered that nginx incorrectly handled certain memory operations in the ngx_http_mp4_module module. A local attacker could possibly use this issue with a specially...
python3.7-3.7.15-2.fc35
FEDORA-2022-760d1eac9b Packages in this update: python3.7-3.7.15-2.fc35 Update description: Security fix for CVE-2022-37454 Read More
DSA-5279 wordpress – security update
Several vulnerabilities were discovered in Wordpress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or...
DSA-5280 grub2 – security update
Several issues were found in GRUB2's font handling code, which could result in crashes and potentially execution of arbitrary code. These could lead to by-pass...
DSA-5281 nginx – security update
It was discovered that parsing errors in the mp4 module of Nginx, a high-performance web and reverse proxy server, could result in denial of service,...
python3.8-3.8.15-2.fc35
FEDORA-2022-7798bf3aa3 Packages in this update: python3.8-3.8.15-2.fc35 Update description: Security fix for CVE-2022-37454 Read More