Source
Packet Storm
ComSndFTP Server version 1.3.7 Beta remote denial of service exploit.
Red Hat Security Advisory 2024-0647-03 - An update for rpm is now available for Red Hat Enterprise Linux 8.
Red Hat Security Advisory 2024-0484-03 - Red Hat OpenShift Container Platform release 4.13.31 is now available with updates to packages and images that fix several bugs and add enhancements.
Ricoh printers suffer from directory and file exposure vulnerabilities.
Typora version 1.7.4 suffers from a command injection vulnerability.
Bank Locker Management System suffers from a remote SQL injection vulnerability.
Grocy versions 4.0.2 and below suffer from a cross site request forgery vulnerabilities.
WebCatalog versions prior to 48.8 call the Electron shell.openExternal function without verifying that the URL is for an http or https resource. This vulnerability allows an attacker to potentially execute code through arbitrary protocols on the victims machine by having users sync pages with malicious URLs. The victim has to interact with the link, which can then enable an attacker to bypass security measures for malicious file delivery.
7 Sticky Notes version 1.9 suffers from a command injection vulnerability.
This archive contains all of the 140 exploits added to Packet Storm in January, 2024.