Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2023-39151: Jenkins Security Advisory 2023-07-26

Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.

CVE
#xss#csrf#vulnerability#web#git#java#perl#oauth#auth#gradle
Apple Security Advisory 2023-07-24-4

Apple Security Advisory 2023-07-24-4 - macOS Ventura 13.5 addresses bypass, code execution, out of bounds read, and use-after-free vulnerabilities.

GHSA-9q9v-qgwx-84mr: Command injection in PaddlePaddle

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

GHSA-hh7p-hvm3-rg88: Heap buffer overflow in PaddlePaddle

Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

GHSA-cv2j-922j-hr56: Float point exception (FPE) in paddlepaddle

FPE in paddle.linalg.matrix_power in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service.

GHSA-rr46-m366-gm44: Null pointer dereference in PaddlePaddle

Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service.

GHSA-8wfh-qxxv-3q8c: Use after free in PaddlePaddle

Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition.

CVE-2023-38673: Paddle/security/advisory/pdsa-2023-005.md at develop · PaddlePaddle/Paddle

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

CVE-2023-38672: Paddle/security/advisory/pdsa-2023-004.md at develop · PaddlePaddle/Paddle

FPE in paddle.trace in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service.

Data theft extortion rises, while healthcare is still most-targeted vertical in Talos IR engagements

Ransomware was the second most-observed threat this quarter, accounting for 17 percent of engagements, a slight increase from last quarter’s 10 percent.