[UPDATE] [critical] GNU libc: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate files, cause a denial-of-service condition, or carry out other unspecified attacks.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate files, cause a denial-of-service condition, or carry out other unspecified attacks.
A remote, authenticated attacker can exploit a vulnerability in Red Hat OpenShift Container Platform to bypass security measures.
An attacker can exploit multiple vulnerabilities in OpenSSL to conduct a denial of service attack, disclose sensitive information, or perform other unspecified attacks.
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Internet Systems Consortium BIND to conduct a denial of service attack or bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in the KDE "Konsole" application to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in GitLab to bypass security measures, conduct cross-site scripting attacks, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perfo…
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured v…
An attacker can exploit multiple vulnerabilities in NGINX and NGINX Plus to manipulate data, execute arbitrary code, disclose confidential information, or trigger a denial-of-service condition.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Check Point SmartConsole to gain elevated privileges, including administrator access, or execute arbitrary code – even with root rights.
An attacker can exploit multiple vulnerabilities in FreeBSD Project FreeBSD OS to escalate privileges, manipulate data, or disclose confidential information.
An attacker can exploit multiple vulnerabilities in NGINX NGINX Plus to execute arbitrary code, carry out a Denial of Service attack, manipulate data, and disclose information.
An attacker can exploit multiple vulnerabilities in Drupal (Token Content Access, Disable Login Page and Powerful Surveys) to bypass security measures and cause unspecified impacts.
An attacker can exploit multiple vulnerabilities in Flowise to execute arbitrary code – even with root privileges – gain elevated privileges, bypass security measures, hijack sessions, and disclose or manipulate data.
A remote, anonymous attacker can exploit a vulnerability in nmap to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in drawio to conduct a cross-site scripting attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Autodesk AutoCAD to execute arbitrary program code with the service's rights, disclose information, or cause a denial of service.
A remote, anonymous attacker can exploit multiple vulnerabilities in SQLite to execute arbitrary program code, disclose information, or cause a denial of service.
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills "val" when handling in-kernel PIO. vcpu…
An attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary code, disclose confidential information, bypass security measures, manipulate data, or trigger a denial-of-service condition.
A remote, authenticated attacker can exploit a vulnerability in Red Hat Quay to disclose information that can be used to impersonate certain accounts.
An attacker can exploit a vulnerability in Red Hat OpenStack Neutron to manipulate data and bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Apache log4j to disclose information.
A remote, anonymous attacker can exploit a vulnerability in libtasn1 to carry out a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in libxml2 to conduct a Denial of Service attack.
A remote, authenticated attacker can exploit a vulnerability in OpenSSH to bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in the SCP component of several products to disclose and manipulate data.
A remote, anonymous attacker can exploit a vulnerability in Cisco Secure Firewall Management Center to disclose information.
A local attacker can exploit a vulnerability in the Linux Kernel for privilege escalation, as well as to create a denial of service condition or other unspecified impacts.
An attacker can exploit multiple vulnerabilities in MariaDB to conduct an unspecified attack.
An attacker can exploit multiple vulnerabilities in PostgreSQL to execute arbitrary program code, carry out a denial-of-service attack, disclose information, manipulate files, conduct an SQL injection attack, and bypass security measures.
A remote anonymous attacker can exploit multiple vulnerabilities in Kiali for Red Hat OpenShift Service Mesh to gain elevated privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.
A remote, authenticated attacker can exploit a vulnerability in TeamViewer to bypass security measures.
A remote, authenticated attacker can exploit a vulnerability in PackageKit to bypass security measures.
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to bypass security measures and execute arbitrary code.
A remote, anonymous attacker can exploit a vulnerability in ImageMagick to carry out an unspecified attack.
A local attacker can exploit a vulnerability in the Linux Kernel to elevate their privileges.
An attacker can exploit multiple vulnerabilities in PHP to execute arbitrary code, perform SQL injection or cross-site scripting attacks, manipulate data, disclose confidential information, or cause a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate data, disclose confidential information, or…
A local attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to escalate their privileges and manipulate data.