[UPDATE] [medium] Aqua Security Trivy: Vulnerability allows denial of service
A remote, anonymous attacker can exploit a vulnerability in Aqua Security Trivy to conduct a denial of service attack.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
A remote, anonymous attacker can exploit a vulnerability in Aqua Security Trivy to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in Aqua Security Trivy to manipulate files.
An attacker can exploit multiple vulnerabilities in Microsoft Windows products to escalate privileges, execute arbitrary code, conduct a Denial of Service attack, disclose information, present false information, manipulate data, and bypass security measures.
An attacker can exploit multiple vulnerabilities in Unbound to perform a denial of service attack, disclose information, manipulate data, and bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in LibreOffice to conduct an unspecified attack.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to trigger a Denial of Service and achieve unspecified effects.
An attacker can exploit multiple vulnerabilities in FreeRDP to conduct a denial of service attack and bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in ffmpeg to cause memory corruption, execute arbitrary code, trigger a denial-of-service condition, or disclose confidential information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Microsoft Edge to disclose information or conduct spoofing attacks.
A local attacker can exploit multiple vulnerabilities in vim to execute arbitrary program code with user privileges, trigger a denial-of-service condition, or disclose confidential information.
A local attacker can exploit multiple vulnerabilities in LibreOffice to conduct an unspecified attack.
An attacker can exploit multiple vulnerabilities in GnuTLS to bypass security measures, disclose confidential information, cause a denial-of-service condition, or perform other unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in ProFTPD to conduct an SQL injection attack.
A remote, anonymous attacker can exploit a vulnerability in Golang Go to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in X.Org X11 and Xwayland to disclose information, escalate privileges, conduct a denial of service attack, and perform an unspecified attack.
SolarWinds has fixed multiple vulnerabilities in Serv-U. The vulnerabilities in SolarWinds Serv-U mainly involve insecure direct object reference (IDOR) and broken access control. These allow attackers with certain privileges, such as domain administrator or group administrator a…
A remote, anonymous attacker can exploit multiple vulnerabilities in Apache Tomcat and Tomcat Native to disclose information and bypass security measures.
A local attacker can exploit a vulnerability in the Linux Kernel to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in Evince to execute arbitrary code.
A remote, authenticated attacker can exploit multiple vulnerabilities in Cpython to manipulate files or execute arbitrary code.
A local attacker can exploit a vulnerability in the Linux Kernel to carry out a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in the Linux Kernel to carry out a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in Red Hat OpenShift to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Golang Go to conduct a denial of service attack.
A remote, authenticated attacker can exploit multiple vulnerabilities in Redis to execute arbitrary program code.
A remote, authenticated attacker can exploit a vulnerability in Checkmk to bypass security measures and manipulate files.
An attacker can exploit a vulnerability in Webmin to bypass security measures.
A remote, authenticated attacker can exploit multiple vulnerabilities in Keycloak to disclose information.
A remote, anonymous attacker can exploit a vulnerability in OpenCTI to bypass security measures and disclose information.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct an unspecified attack, potentially to manipulate or disclose data, bypass security measures, or cause a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Apache Tomcat to bypass security measures, manipulate data, disclose confidential information, conduct open redirect attacks, and carry out other unspecified attacks.
A remote, authenticated attacker can exploit a vulnerability in Octopus Deploy to bypass security precautions.
A remote, anonymous attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary program code, bypass security mechanisms, or achieve other unspecified impacts.
A remote, anonymous attacker can exploit a vulnerability in ffmpeg to conduct a Denial of Service attack.
A local attacker can exploit a vulnerability in Red Hat Enterprise Linux to execute arbitrary code, disclose confidential information, or cause a Denial-of-Service condition.
An attacker can exploit multiple vulnerabilities in Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
A local attacker can exploit multiple vulnerabilities in Exim to execute arbitrary commands and escalate privileges.
An attacker can exploit a vulnerability in Google Cloud Platform to conduct a cross-site scripting attack.
Multiple vulnerabilities have been discovered in Atlassian products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
Multiple vulnerabilities have been discovered in GLPI. Some of them allow an attacker to cause privilege escalation, data integrity issues, and SQL injection (SQLi).
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP …
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of th…
A vulnerability has been discovered in Traefik. It allows an attacker to bypass the security policy.
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause data privacy issues, bypass the security policy, and an unspecified security issue by the vendor.
Impact _What kind of vulnerability is it? Who is impacted?_ A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Ha…
Summary The OpenAPI adapter's spec-change poller (OpenApiSpecPoller) re-fetched the configured spec url on a timer using a raw global fetch(), bypassing the SSRF guard (safeFetch / assertUrlSafe) that OpenAPIToolGenerator.fromURL() applies to the initial spec load. As a result, …
| Field | Value | |---|---| | Ecosystem | Go | | Package | github.com/getkin/kin-openapi | | Affected versions | <= 0.143.0 (introduced in v0.2.0, PR #90, 2019-05-07; reproduced on HEAD 30e2923) | | Patched versions | 0.144.0 | Summary openapi3filter.ValidateRequest contains a …
Summary The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. An issue exists where, under certain circumstances, improper neutralization of argume…
Impact _What kind of vulnerability is it? Who is impacted?_ A user granted READ permission on a single, exact key can use the Watch gRPC API with clientv3.WithFromKey() (an open-ended, "from this key to the end of the keyspace" watch) to receive watch events for every key lexico…