An update that fixes three vulnerabilities is now available.
jQuery mishandles jQuery.extend(true, {}, …) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. For additional information, please refer to the upstream advisory at
* Mouse cursor doubled on QEMU VNC on ppc64le (bz #1565253) * CVE-2019-3840: NULL deref after running qemuAgentGetInterfaces (bz #1665229)
This update provides an update to the new Virtualbox 6.0 branch, currently 6.0.6. It also fixes the following security issues. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise
An update that solves 13 vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that fixes 19 vulnerabilities is now available.
An update that solves four vulnerabilities and has one errata is now available.
An update that fixes 16 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
Colin Snover discovered a denial-of-service vulnerability in phpBB3, a full-featured web forum. Previous versions allowed users to run searches that might result in long execution times and load on larger boards when using the fulltext native search engine. To combat this, further
Security fix for CVE-2019-3885, CVE-2018-16877, CVE-2018-16878
Update to April 2019 CPU. See: http://mail.openjdk.java.net/pipermail/jdk- updates-dev/2019-April/000951.html
New upstream release with significantly reworked PKCS#11 support, GSSAPI key exchange and several fixes for CVE-2019-6111 and CVE-2019-6109
New upstream release
Reading Time: ~2 min. “FBI Director” Phishing Campaign A new email phishing campaign has been making its way around the web that claims to be from “FBI Director Christopher Wray,” who would love to assist with a massive wire transfer to the victim’s bank account. Unfortunately for anyone hoping for a quick payday, the $10 […]
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
An update that fixes 18 vulnerabilities is now available.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
So, do you think you’ve been ‘pwned’? That’s the question to ask yourself today The post World Password Day: A day to review your defenses appeared first on WeLiveSecurity
Several security issues were fixed in python-gnupg
An update that fixes two vulnerabilities is now available.
ESET researchers highlight a series of security holes in a device intended to make homes and offices more secure The post D-Link camera vulnerability allows attackers to tap into the video stream appeared first on WeLiveSecurity
**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.
**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).
**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.
**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).
An update that fixes two vulnerabilities is now available.
An update that solves 5 vulnerabilities and has 5 fixes is now available.
An update that contains security fixes can now be installed.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
An unsafe shell call enabling shell injection via a user ID was corrected in gpg-key2ps, a tool to generate a PostScript file with OpenPGP key fingerprint slips.
The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719).
Memcached could be made to crash if it received specially crafted network traffic.
