Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. SAP Financial Consolidation is prone to multiple unspecified security vulnerabilities; fixes are available.
Type: Vulnerability. SAP NetWeaver Process Integration is prone to an authorization-bypass vulnerability; fixes are available.
Type: Vulnerability. SAP Customer Relationship Management (CRM) is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. SAP NetWeaver Process Integration is prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. SAP BusinessObjects Business Intelligence Platform is prone to multiple cross-site scripting vulnerabilities; fixes are available.
Type: Vulnerability. Multiple SAP Products are prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. SAP Landscape Management is prone to an unspecified information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Cisco Adaptive Security Appliance is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. GitLab Omnibus is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to a directory-traversal vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to a local privilege-escalation vulnerability.
Type: Vulnerability. Apache MINA is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Threat Defense Software is prone to a local command-injection vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center Software is prone to a remote security-bypass vulnerability; fixes are available.
Type: Vulnerability. Apache Hadoop is prone to a memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Android-gif-drawable is prone to a remote code execution vulnerability; fixes are available.
Type: Vulnerability. Cisco Email Security Appliance is prone to a remote security-bypass vulnerability; fixes are available.
Type: Vulnerability. Cisco IC3000 Industrial Compute Gateway is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Unified Communications Manager is prone to an SQL-injection vulnerability; fixes are available.
Type: Vulnerability. Cisco Identity Services Engine is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco Unified Communications Manager is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Cisco Security Manager is prone to a command-execution vulnerability; fixes are available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
In lib/mini_magick/image.rb in ruby-mini-magick, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a ‘|’ character
Several security issues were fixed in OpenEXR.
CVE-2019-16993 In phpBB, includes/acp/acp_bbcodes.php had improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An
An update that solves two vulnerabilities and has one errata is now available.
– Update to 2.16.3 – Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.3-and-2.7.12-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2019-10
– Update to 2.16.3 – Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.3-and-2.7.12-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2019-10
This is an update fixing CVE-2019-16928.
Update to 1.7.5 —- Fixes CVE-2019-12816
security update
security update
1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of
Max Kellermann reported a NULL pointer dereference flaw in libapreq2, a generic Apache request library, allowing a remote attacker to cause a denial of service against an application using the library (application crash) if an invalid nested “multipart” body is processed.
1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of
1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of
An XSS vulnerability was discovered in noVNC in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
An update that fixes 29 vulnerabilities is now available.
Type: Vulnerability. Linux Kernel is prone to multiple local privilege-escalation vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Unified Contact Center Express is prone to an HTTP response-splitting vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Adaptive Security Appliance is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Moxa EDR 810 Series is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.
The package ruby2.5 before version 2.5.7-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, cross-site scripting, denial of service and insufficient validation.
The package ruby-rdoc before version 6.1.2-1 is vulnerable to cross- site scripting.
An update that fixes 27 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 27 vulnerabilities is now available.
