Type: Vulnerability. Cisco Small Business RV Series Routers are prone to a remote command injection vulnerability; fixes are available.
Type: Vulnerability. Cisco Web Security Appliance is prone to a cross-site scripting vulnerability; fixes are available.
New kernel packages are available for Slackware 14.2 to fix security issues.
Reading Time: ~ 2 min. BEC Scam Takes Millions from Nikkei America Officials for Nikkei are working to identify the perpetrators of a recent business email compromise (BEC) scam that took roughly $29 million from the company’s American subsidiary. The illicit transfer took place sometime during the end of September and, though they did make […]
An update that fixes one vulnerability is now available.
Applications using FriBidi could be made to crash or run programs as your login if it displayed specially crafted text.
security update
Alex Murray discovered a stack-based buffer overflow vulnerability in fribidi, an implementation of the Unicode Bidirectional Algorithm algorithm, which could result in denial of service or potentially the execution of arbitrary code, when processing a large number of unicode
security update
It was discovered that Expat did not properly handle internal entities closing the doctype, potentially resulting in denial of service or information disclosure if a malformed XML file is processed (CVE-2019-15903).
Chromium-browser 78.0.3904.87 fixes security issues: Multiple flaws were found in the way Chromium 77.0.3865.120 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose
Updated freetds packages fix security vulnerability: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly
Updated python and python3 packages fix security vulnerabilities: It was discovered that Python incorrectly parsed certain email addresses. A remote attacker could possibly use this issue to trick Python applications into accepting email addresses that should be denied (CVE-2019-16056).
Updated unbound packages fix security vulnerability: Versions before 1.9.4 allow accesses to uninitialized memory, which would permit remote attackers to trigger a crash (CVE-2019-16866).
The updated packages fix security issues: Use-after-free when creating index updates in IndexedDB. (CVE-2019-11757)
The updated packages fix several bugs and some security issues: Use-after-free when creating index updates in IndexedDB. (CVE-2019-11757)
Updated proftpd package fixes security vulnerabilities: It was discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands (CVE-2019-12815).
Type: Vulnerability. Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Web Security Appliance is prone to an unauthorized-access vulnerability; fixes are available
Type: Vulnerability. Multiple Cisco Products are prone to an remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Cisco TelePresence Advanced Media Gateway is prone to a remote denial-of-service vulnerability.
Type: Vulnerability. Cisco Industrial Network Director is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. libarchive is prone to an arbitrary code-execution vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities.
Type: Vulnerability. Google Android is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities; fixes are available.
Type: Vulnerability. Joomla! Core is prone to an information-disclosure vulnerability; fixes are available.
The package linux-hardened before version 5.3.7.b-1 is vulnerable to arbitrary code execution.
An update for cri-o is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for mediawiki123 is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Several security issues were fixed in WebKitGTK+.
An update that fixes 9 vulnerabilities is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
Type: Vulnerability. Joomla! is prone to a cross-site request-forgery vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to multiple information-disclosure vulnerabilities; fixes are available.
Type: Vulnerability. MantisBT is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to a remote code execution vulnerability; fixes are available.
Type: Vulnerability. Red Hat ‘389-ds-base’ is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Sonatype Nexus Repository Manager is prone to an OS command-injection vulnerability; fixes are available.
security update
Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a cross-site scripting vulnerability.
