Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, spoof the browser UI, conduct cross-site scripting (XSS)
attacks, bypass content security policy (CSP) restrictions, or execute
arbitrary code.
Category Archives: Advisories
openssl-1.1.1o-1.fc35
FEDORA-2022-c9c02865f6
Packages in this update:
openssl-1.1.1o-1.fc35
Update description:
Security fix for CVE-2022-1292
Upgrade to 1.1.1o, #2095817.
openssl1.1-1.1.1o-1.fc36
FEDORA-2022-b651cb69e6
Packages in this update:
openssl1.1-1.1.1o-1.fc36
Update description:
Security fix for CVE-2022-1292
Upgrade to 1.1.1o, rhbz#2095817.
openssl1.1-1.1.1o-1.fc37
FEDORA-2022-412d83c1f9
Packages in this update:
openssl1.1-1.1.1o-1.fc37
Update description:
Automatic update for openssl1.1-1.1.1o-1.fc37.
Changelog
* Mon Jun 13 2022 Clemens Lang <cllang@redhat.com> – 1:1.1.1o-1
– Upgrade to 1.1.1o
Resolves: CVE-2022-1292
Related: rhbz#2095817
python-bottle-0.12.21-2.el8
FEDORA-EPEL-2022-17d14b279e
Packages in this update:
python-bottle-0.12.21-2.el8
Update description:
Cookie test fix backported from upstream (0.12)
Security fix for CVE-2022-31799
python-bottle-0.12.21-2.el9
FEDORA-EPEL-2022-6812bb3862
Packages in this update:
python-bottle-0.12.21-2.el9
Update description:
Cookie test fix backported from upstream (0.12)
Security fix for CVE-2022-31799
python-bottle-0.12.21-2.fc35
FEDORA-2022-c1e107f37f
Packages in this update:
python-bottle-0.12.21-2.fc35
Update description:
Cookie test fix backported from upstream (0.12)
Security fix for CVE-2022-31799
python-bottle-0.12.21-2.fc36
FEDORA-2022-cc9a173168
Packages in this update:
python-bottle-0.12.21-2.fc36
Update description:
Cookie test fix backported from upstream (0.12)
Security fix for CVE-2022-3179
CVE-2017-20042
A vulnerability has been found in Navetti PricePoint 4.6.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection (Blind). The attack can be launched remotely. Upgrading to version 4.7.0.0 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20043
A vulnerability was found in Navetti PricePoint 4.6.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting (Persistent). The attack may be launched remotely. Upgrading to version 4.7.0.0 is able to address this issue. It is recommended to upgrade the affected component.