Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

osCommerce 4 Local File Inclusion

osCommerce version 4 suffers from a local file inclusion vulnerability.

Packet Storm
#vulnerability#windows#google#git#php#auth#firefox
WordPress Workreap 2.2.2 Shell Upload

WordPress theme Workreap version 2.2.2 suffers from a remote shell upload vulnerabilities.

VIVO SPARQL Injection

Proof of concept exploit for a SPARQL injection vulnerability in VIVO that triggers a denial of service.

strongSwan VPN Charon Server Buffer Overflow

Proof of concept exploit for a buffer overflow in strongSwan VPN's charon server.

librelp Remote Code Execution

Proof of concept exploit for a buffer overflow remote code execution vulnerability in librelp.

polkit File Descriptor Exhaustion

Proof of concept exploit for polkit that triggers an eventfd file descriptor leak.

Ubuntu Security Notice USN-6152-1

Ubuntu Security Notice 6152-1 - It was discovered that NFS client's access cache implementation in the Linux kernel caused a severe NFS performance degradation in certain conditions. This updated makes the NFS file-access stale cache behavior to be optional.

Debian Security Advisory 5422-1

Debian Linux Security Advisory 5422-1 - It was discovered that jupyter-core, the core common functionality for Jupyter projects, could execute arbitrary code in the current working directory while loading configuration files.

Movierocket 1.0 Cross Site Scripting

Movierocket version 1.0 suffers from a cross site scripting vulnerability.

Thruk Monitoring Web Interface 3.06 Path Traversal

Thruk Monitoring Web Interface versions 3.06 and below are affected by a path traversal vulnerability.