π¨ CVE-2023-35317
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
π@cveNotify
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
π@cveNotify
π¨ CVE-2023-35313
Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability
π@cveNotify
Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability
π@cveNotify
π¨ CVE-2023-34089
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in version 0.27.3 and 0.26.6.
π@cveNotify
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in version 0.27.3 and 0.26.6.
π@cveNotify
GitHub
Release v0.27.3 Β· decidim/decidim
Security fixes
This release addresses several security issues, including the following:
CVE-2023-32693
CVE-2023-34089
CVE-2023-34090
The details regarding the security vulnerability will be publi...
This release addresses several security issues, including the following:
CVE-2023-32693
CVE-2023-34089
CVE-2023-34090
The details regarding the security vulnerability will be publi...
π¨ CVE-2023-32056
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
π@cveNotify
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
π@cveNotify
π¨ CVE-2023-32039
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
π@cveNotify
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
π@cveNotify
π¨ CVE-2023-30607
icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no known workarounds.
π@cveNotify
icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no known workarounds.
π@cveNotify
GitHub
Do not perform deletion before user input is validated in `FieldConfi⦠· Icinga/icingaweb2-module-jira@7f0c53b
β¦gForm` and `TemplateConfigForm`
This fixes susceptibility to CSRF attacks.
This fixes susceptibility to CSRF attacks.
π¨ CVE-2023-35974
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
π@cveNotify
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
π@cveNotify
π¨ CVE-2023-31248
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
π@cveNotify
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
π@cveNotify
π¨ CVE-2023-34834
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.
π@cveNotify
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.
π@cveNotify
Mcl-Collection
MCL-Collection V4
MCL-Collection V4 offers developers to develop Mobility Applications, cost effectively.
π¨ CVE-2023-25399
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function.
π@cveNotify
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function.
π@cveNotify
GitHub
BUG: Memory leak in function `Py_FindObjects` due to new reference is not decreased (static analyzer report) Β· Issue #16235 Β· scipy/scipy
A new reference is returned and assigned to tuple. scipy/scipy/ndimage/src/nd_image.c Line 888 in 8627df3 PyObject *tuple = PyTuple_New(PyArray_NDIM(input)); Assume tuple is not NULL. scipy/scipy/n...
π¨ CVE-2023-29406
The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.
π@cveNotify
The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.
π@cveNotify