In today’s digital world, passwords have become a necessary part of life. But even though you use them for almost everything you do online, you probably don’t give them the thought they truly deserve. May 1, 2025, is World Password Day, a reminder that passwords are the unsung heroes of cybersecurity, the first line of […]
From the near-demise of MITRE’s CVE program to a report showing that AI outperforms elite red teamers in spearphishing, April 2025 was another whirlwind month in cybersecurity
H2O could be made to crash if it received specially crafted network traffic.
PostgreSQL could be made to execute arbitrary code if it received specially crafted input.
* bsc#1233294 * bsc#1235431 Cross-References: * CVE-2024-50205
* bsc#1239909 Cross-References: * CVE-2025-2588
https://security-tracker.debian.org/tracker/DSA-5908-1
Several security issues were fixed in Mistral.
Several security issues were fixed in Mistral.
Apache Tomcat could be made to crash if it received specially crafted network traffic.
Apache Tomcat could be made to crash if it received specially crafted network traffic.
Your iPhone isn’t necessarily as invulnerable to security threats as you may think. Here are the key dangers to watch out for and how to harden your device against bad actors.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0
Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0
Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208
Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.
Several security vulnerabilities have been discovered in libsoup2.4, a http client/server library popularly used in GNOME, et.al. CVE-2025-2784
Multiple vulnerabilities have been fixed in the PDF rendering library poppler. CVE-2020-36023
* bsc#1241584 * bsc#1241585 Cross-References: * CVE-2015-3885
* bsc#1239680 Cross-References: * CVE-2025-2312
Jupyter Notebook could be made to crash if it received specially crafted input.
Update to 135.0.7049.114
Update to pgadmin-9.2.
April 2025 CPU
April 2025 CPU
April 2025 CPU
April 2025 CPU
https://security-tracker.debian.org/tracker/DSA-5907-1
[CVE-2025-32414] Buffer overflow when parsing text streams with Python API [CVE-2025-32415] Heap-based Buffer Overflow in xmlSchemaIDCFillNodeTables
BUG/MEDIUM: sample: fix risk of overflow when replacing multiple regex back-refsAleandro Prudenzano of Doyensec and Edoardo Geraci of Codean Labs reported a bug in sample_conv_regsub(), which can cause replacements of multiple back-references to overflow the temporary trash buffer. The problem happens when doing “regsub(match,replacement,g)”:
* bsc#1230092 Cross-References: * CVE-2024-45310
Look out for AI-generated ‘TikDocs’ who exploit the public’s trust in the medical profession to drive sales of sketchy supplements
Update to 135.0.7049.114
Update to 135.0.7049.114
New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1
The form and quiz-building tool is a popular vector for social engineering and malware. Here’s how to stay safe.
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
