In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
Category Archives: Advisories
DSA-5230 chromium – security update
Multiple security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
CVE-2020-36603
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user with administrative privileges.
zabbix-6.0.8-1.fc37
FEDORA-2022-0d56cb7ee4
Packages in this update:
zabbix-6.0.8-1.fc37
Update description:
6.0.8, fixes CVE-2022-40626
CVE-2021-38924
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
java-latest-openjdk-18.0.2.0.9-1.rolling.el9
FEDORA-EPEL-2022-3bd4c9e300
Packages in this update:
java-latest-openjdk-18.0.2.0.9-1.rolling.el9
Update description:
July CPU update
java-latest-openjdk-18.0.2.0.9-1.rolling.el8
FEDORA-EPEL-2022-73672e02b0
Packages in this update:
java-latest-openjdk-18.0.2.0.9-1.rolling.el8
Update description:
July CPU update
python3.11-3.11.0~rc2-1.fc36
FEDORA-2022-0b3904c674
Packages in this update:
python3.11-3.11.0~rc2-1.fc36
Update description:
Update Python to 3.11.0rc2. Contains security fix for CVE-2020-10735 and other bugfixes, see https://docs.python.org/3.11/whatsnew/changelog.html#python-3-11-0-release-candidate-2
freeipa-4.10.0-6.fc37 samba-4.17.0-1.fc37
FEDORA-2022-4555909843
Packages in this update:
freeipa-4.10.0-6.fc37
samba-4.17.0-1.fc37
Update description:
Update to version 4.17.0
ZDI-22-1191: Trend Micro Apex One Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.