ZDI-24-1101: Apple macOS Metal Framework KTX Image Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the Metal framework is required to exploit this...
CyberDanube Security Research 20240805-0 | Multiple Vulnerabilities in JetPort Series
Posted by Thomas Weber via Fulldisclosure on Aug 05 CyberDanube Security Research 20240805-0 ------------------------------------------------------------------------------- title| Multiple Vulnerabilities in JetPort Series product| Korenix JetPort Series vulnerable...
CVE-2024-40101 exploit: Reflected Cross-Site Scripting (XSS) on Microweber
Posted by masquerad3r on Aug 05 Hello team, Please find the attached POC for CVE-2024-40101 for publication. Regards, Prerak Mittal # Exploit Title: Microweber <=v2.0.15...
GLSA 202408-02: Mozilla Firefox: Multiple Vulnerabilities
Post Content Read More
GLSA 202408-01: containerd: Multiple Vulnerabilities
Post Content Read More
DSA-5738-1 openjdk-17 – security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions....
DSA-5739-1 wpa – security update
Rory McNamara reported a local privilege escalation in wpasupplicant: A user able to escalate to the netdev group can load arbitrary shared object files in...
microcode_ctl-2.1-61.1.fc40
FEDORA-2024-96f3c3f3d3 Packages in this update: microcode_ctl-2.1-61.1.fc40 Update description: Update to upstream 2.1-43. 20240531 Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c; Addition of 06-ba-08/0xe0...
microcode_ctl-2.1-58.1.fc39
FEDORA-2024-f3692f8528 Packages in this update: microcode_ctl-2.1-58.1.fc39 Update description: Update to upstream 2.1-43. 20240531 Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c; Addition of 06-ba-08/0xe0...
USN-6944-1: curl vulnerability
Dov Murik discovered that curl incorrectly handled parsing ASN.1 Generalized Time fields. A remote attacker could use this issue to cause curl to crash, resulting...