Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

Ubuntu Security Notice USN-6148-1

Ubuntu Security Notice 6148-1 - It was discovered that SNI Proxy did not properly handle wildcard backend hosts. An attacker could possibly use this issue to cause a buffer overflow, resulting in a denial of service, or arbitrary code execution.

Packet Storm
#vulnerability#ubuntu#dos#perl#buffer_overflow#ssl
Ubuntu Security Notice USN-6156-1

Ubuntu Security Notice 6156-1 - It was discovered that SSSD incorrectly sanitized certificate data used in LDAP filters. When using this issue in combination with FreeIPA, a remote attacker could possibly use this issue to escalate privileges.

Ubuntu Security Notice USN-6155-1

Ubuntu Security Notice 6155-1 - Dennis Brinkrolf and Tobias Funke discovered that Requests incorrectly leaked Proxy-Authorization headers. A remote attacker could possibly use this issue to obtain sensitive information.

Ubuntu Security Notice USN-6154-1

Ubuntu Security Notice 6154-1 - It was discovered that Vim was using uninitialized memory when fuzzy matching, which could lead to invalid memory access. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. It was discovered that Vim was not properly performing bounds checks when processing register contents, which could lead to a NULL pointer dereference. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.

ProLogin 1.9 Insecure Direct Object Reference

ProLogin version 1.9 suffers from an insecure direct object reference vulnerability.

Piyanas 0.1 Cross Site Request Forgery

Piyanas version 0.1 suffers from a cross site request forgery vulnerability.

phpAnalyzer 2.0.4 Insecure Settings

phpAnalyzer version 2.0.4 appears to leave default credentials installed after installation.

EasyAnswer 1.0.1 Cross Site Request Forgery

EasyAnswer version 1.0.1 suffers from a cross site request forgery vulnerability.

Online Thesis Archiving System 1.0 SQL Injection

Online Thesis Archiving System version 1.0 suffers from a remote SQL injection vulnerability.

Xoops CMS 2.5.10 Cross Site Scripting

Xoops CMS version 2.5.10 suffers from a persistent cross site scripting vulnerability.