Category Archives: Advisories

ZDI-22-1225: Adobe InDesign SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

Read Time:11 Second

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe InDesign. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Read More

CVE-2020-19587

Read Time:8 Second

Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.

Read More

CVE-2021-36568

Read Time:18 Second

In certain Moodle products after creating a course, it is possible to add in a arbitrary “Topic” a resource, in this case a “Database” with the type “Text” where its values “Field name” and “Field description” are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.

Read More

ImageMagick-6.9.12.63-1.el8

Read Time:12 Second

FEDORA-EPEL-2022-9d8794e452

Packages in this update:

ImageMagick-6.9.12.63-1.el8

Update description:

Update ImageMagick to 6.9.12.63 (#2125990)

Update ImageMagick to 6.9.12.62 (#2121962)

Fixes CVE-2021-3574 (#2124540, #2124541, #2124542)

Read More