Posted by Nick Boyce on Apr 13
[Complete Apple product novice here (my devices all run a non-Apple
OS), but I’m asking for a friend]
Could someone please clarify the following part of the advisory for me:
Does this mean the update will be available via the “Software Update”
feature on an iPhone – or not ?
The quoted paragraph of Apple’s advisory is a bit
Schroedinger’s-Cat-ish – the update is both available and not
available.
Thanks,
Nick
[…]…
Posted by Egidio Romano on Apr 13
————————————————————————————
UNA CMS <= 14.0.0-RC4 (BxBaseMenuSetAclLevel.php) PHP Object Injection
Vulnerability
————————————————————————————
[-] Software Links:
https://unacms.com
https://github.com/unacms/una
[-] Affected Versions:
All versions from 9.0.0-RC1 to 14.0.0-RC4.
[-] Vulnerability Description:
The vulnerability…
Posted by Martin Heiland via Fulldisclosure on Apr 13
Dear subscribers,
We’re sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those
vulnerabilities. Feel free to join our bug bounty programs for OX App Suite, Dovecot and PowerDNS at YesWeHack.
This advisory has also been published at
https://documentation.open-xchange.com/appsuite/security/advisories/html/2025/oxas-adv-2025-0001.html .
Yours sincerely,
Martin Heiland, Open-Xchange…
FEDORA-2025-3467f5b68d
Packages in this update:
trafficserver-9.2.10-1.fc40
Update description:
Resolves CVE-2024-53868
FEDORA-EPEL-2025-5aa53e9dd0
Packages in this update:
trafficserver-9.2.10-1.el9
Update description:
Resolves CVE-2024-53868
FEDORA-2025-76d6ce0e17
Packages in this update:
trafficserver-10.0.5-1.fc42
Update description:
Resolves CVE-2024-53868
FEDORA-EPEL-2025-36ee2e808c
Packages in this update:
trafficserver-9.2.10-1.el8
Update description:
Resolves CVE-2024-53868
FEDORA-2025-7c4a6154e5
Packages in this update:
trafficserver-9.2.10-1.fc41
Update description:
Resolves CVE-2024-53868
FEDORA-2025-0f2d318242
Packages in this update:
chromium-135.0.7049.84-1.fc42
Update description:
Update to 135.0.7049.84
CVE-2025-3066: Use after free in Site Isolation
Nathan Mills discovered a heap-based buffer overflow vulnerability in
the implementation of the Perl programming language when transliterating
non-ASCII bytes with tr///, which may result in denial of service, or
potentially the execution of arbitrary code.
https://security-tracker.debian.org/tracker/DSA-5902-1
Posts navigation
News, Advisories and much more