๐จ CVE-2026-63071
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security sandbox.
๐@cveNotify
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security sandbox.
๐@cveNotify
๐จ CVE-2026-63091
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process memory into the uploaded file. In tested configurations, the disclosed data contains libc, libcrypto, and PIE pointers sufficient to derive their randomized base addresses, thereby bypassing ASLR and enabling reliable exploitation of memory corruption vulnerabilities in the same process.
๐@cveNotify
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process memory into the uploaded file. In tested configurations, the disclosed data contains libc, libcrypto, and PIE pointers sufficient to derive their randomized base addresses, thereby bypassing ASLR and enabling reliable exploitation of memory corruption vulnerabilities in the same process.
๐@cveNotify
GitHub
proftpd/RELEASE_NOTES at master ยท proftpd/proftpd
ProFTPD source code. Contribute to proftpd/proftpd development by creating an account on GitHub.
๐จ CVE-2024-30062
Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability
๐@cveNotify
Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability
๐@cveNotify
๐จ CVE-2024-30063
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
๐@cveNotify
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
๐@cveNotify
๐จ CVE-2024-30069
Windows Remote Access Connection Manager Information Disclosure Vulnerability
๐@cveNotify
Windows Remote Access Connection Manager Information Disclosure Vulnerability
๐@cveNotify
๐จ CVE-2024-30072
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability
๐@cveNotify
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability
๐@cveNotify
๐จ CVE-2024-30074
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
๐@cveNotify
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
๐@cveNotify
๐จ CVE-2024-30075
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
๐@cveNotify
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
๐@cveNotify
๐จ CVE-2024-30076
Windows Container Manager Service Elevation of Privilege Vulnerability
๐@cveNotify
Windows Container Manager Service Elevation of Privilege Vulnerability
๐@cveNotify
๐จ CVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
๐@cveNotify
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
๐@cveNotify
๐จ CVE-2024-30083
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
๐@cveNotify
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
๐@cveNotify