ZDI-24-1471: Panda Security Dome PSANHost Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged...
USN-7098-1: OpenJDK 17 vulnerabilities
Andy Boothe discovered that the Networking component of OpenJDK 17 did not properly handle access under certain circumstances. An unauthenticated attacker could possibly use this...
USN-7097-1: OpenJDK 11 vulnerabilities
Andy Boothe discovered that the Networking component of OpenJDK 11 did not properly handle access under certain circumstances. An unauthenticated attacker could possibly use this...
USN-7096-1: OpenJDK 8 vulnerabilities
Andy Boothe discovered that the Networking component of OpenJDK 8 did not properly handle access under certain circumstances. An unauthenticated attacker could possibly use this...
DSA-5809-1 symfony – security update
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to privilege escalation, information disclosure, incorrect validation or an open redirect. https://security-tracker.debian.org/tracker/DSA-5809-1...
DSA-5808-1 ghostscript – security update
Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code...
DSA-5811-1 mpg123 – security update
An out-of-bounds write vulnerability when handling crafted streams was discovered in mpg123, a real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3,...
DSA-5810-1 chromium – security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-5810-1 Read More
USN-7099-1: OpenJDK 21 vulnerabilities
Andy Boothe discovered that the Networking component of OpenJDK 21 did not properly handle access under certain circumstances. An unauthenticated attacker could possibly use this...
lemonldap-ng-2.20.1-1.el8
FEDORA-EPEL-2024-c35d90e5f2 Packages in this update: lemonldap-ng-2.20.1-1.el8 Update description: Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by "Refresh my rights" [Security] XSS in upgradeSession...