Re: [SYSS-2024-038] DiCal-RED – Use of Password Hash Instead of Password for Authentication
Posted by Jeffrey Walton on Aug 24 There's no difference between sending the password or Hash(password) at the client. It is similar to (but weaker...
SCHUTZWERK-SA-2024-004: Buffer overread in U-Boot DHCP
Posted by David Brown via Fulldisclosure on Aug 24 Title ===== SCHUTZWERK-SA-2024-004: Buffer overread in U-Boot DHCP Status ====== PUBLISHED Version ======= 1.0 CVE reference...
calibre-7.17.0-2.fc40
FEDORA-2024-6f1ed8b501 Packages in this update: calibre-7.17.0-2.fc40 Update description: Upgrade to latest upstream release to fix 4 CVE's and enable new hardware Read More
Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk (WHD), the most severe of which could allow for remote code execution. Web Help Desk...
USN-6974-2: Linux kernel (Oracle) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the...
USN-6972-3: Linux kernel (Azure) vulnerabilities
Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux Kernel contained a race condition, leading to a NULL pointer dereference. An attacker...
USN-6973-2: Linux kernel (Azure) vulnerabilities
It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A privileged...
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe...
ZDI-24-1178: Qualcomm Wi-Fi SON LDB Service Improper Input Validation Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple Qualcomm chipsets. Authentication is not required to exploit this vulnerability. The...
ZDI-24-1177: Amazon AWS my-cute-s3-bucket Uncontrolled Search Path Element Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Amazon AWS. Authentication is not required to exploit this vulnerability. The ZDI...