ZDI-24-1105: Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability
This vulnerability allows remote attackers to delete arbitrary directories on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The...
ZDI-24-1104: Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability
This vulnerability allows local attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The ZDI...
ZDI-24-1103: Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability
This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The...
USN-6947-1: Kerberos vulnerabilities
It was discovered that Kerberos incorrectly handled GSS message tokens where an unwrapped token could appear to be truncated. An attacker could possibly use this...
DSA-5741-1 chromium – security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-5741-1 Read More
DSA-5743-1 roundcube – security update
Multiple cross-site scripting vulnerabilities were discovered in RoundCube webmail. https://security-tracker.debian.org/tracker/DSA-5743-1 Read More
DSA-5742-1 odoo – security update
A vulnerability was discovered in odoo, a suite of web based open source business apps. It could result in the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-5742-1...
DSA-5744-1 thunderbird – security update
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-5744-1 Read More
KL-001-2024-010: Journyx Unauthenticated XML External Entities Injection
Posted by KoreLogic Disclosures via Fulldisclosure on Aug 07 KL-001-2024-010: Journyx Unauthenticated XML External Entities Injection Title: Journyx Unauthenticated XML External Entities Injection Advisory ID:...
KL-001-2024-009: Journyx Reflected Cross Site Scripting
Posted by KoreLogic Disclosures via Fulldisclosure on Aug 07 KL-001-2024-009: Journyx Reflected Cross Site Scripting Title: Journyx Reflected Cross Site Scripting Advisory ID: KL-001-2024-009 Publication...