This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13046.
Category Archives: Advisories
ZDI-24-1729: (0Day) Ashlar-Vellum Cobalt AR File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13045.
ZDI-24-1728: (0Day) Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13044.
ZDI-24-1727: (0Day) Panda Security Dome Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13043.
DSA-5838-1 gst-plugins-good1.0 – security update
Multiple vulnerabilities were discovered in plugins for the GStreamer
media framework and its codecs and demuxers, which may result in denial
of service or potentially the execution of arbitrary code if a malformed
media file is opened.
ofono-2.14-1.fc40
FEDORA-2024-112fde4e1b
Packages in this update:
ofono-2.14-1.fc40
Update description:
Update to v2.14
icecat-flatpak-115.18.0-2
FEDORA-FLATPAK-2024-5ad8ccec67
Packages in this update:
icecat-flatpak-115.18.0-2
Update description:
Updated patchset for CVE-2024-11693 CVE-2024-11697 CVE-2024-11692
mupdf-1.24.6-2.fc40
FEDORA-2024-bfc5e25437
Packages in this update:
mupdf-1.24.6-2.fc40
Update description:
fix CVE-2024-46657 (rhbz#2331626)
mupdf-1.21.1-6.el9
FEDORA-EPEL-2024-94a20f339a
Packages in this update:
mupdf-1.21.1-6.el9
Update description:
fix CVE-2024-46657 (rhbz#2331625)
DSA-5837-1 fastnetmon – security update
Two security issues have been discovered in FastNetMon, a fast DDoS
analyzer: Malformed Netflow/sFlow traffic could result in denial of
service.