Security
Headlines
HeadlinesLatestCVEs

Tag

#git

SMTP Smuggling: New Flaw Lets Attackers Bypass Security and Spoof Emails

A new exploitation technique called Simple Mail Transfer Protocol (SMTP) smuggling can be weaponized by threat actors to send spoofed emails with fake sender addresses while bypassing security measures. "Threat actors could abuse vulnerable SMTP servers worldwide to send malicious emails from arbitrary email addresses, allowing targeted phishing attacks," Timo Longin, a senior security

The Hacker News
#vulnerability#microsoft#cisco#git#auth#The Hacker News
GHSA-4rrv-8gcp-24v8: PaddlePaddle stack overflow in paddle.searchsorted

Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

GHSA-3cr5-2446-8pg3: PaddlePaddle command injection in convert_shape_compare

PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

GHSA-g57v-2687-jx33: PaddlePaddle stack overflow in paddle.linalg.lu_unpack

Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

GHSA-rg9q-m8hv-xxr6: PaddlePaddle floating point exception in paddle.lerp

FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

GHSA-j5h9-9r39-43q5: PaddlePaddle command injection in get_online_pass_interval

PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.

GHSA-8fp7-jwv2-49x9: PaddlePaddle heap buffer overflow in paddle.repeat_interleave

Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

GHSA-rx2r-q96c-w5cc: PaddlePaddle floating point exception in paddle.topk

FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

GHSA-rf7p-79xq-8xwm: PaddlePaddle command injection in _wget_download

PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.

GHSA-v9pg-qw6x-w5r2: PaddlePaddle floating point exception in paddle.amin

FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.