Stripe: Local applications from user’s computer can listen for webhooks via insecure gRPC server from stripe-cli

The stripe daemon command from the stripe-cli exposes a local gRPC server that does not require authentication and allows any local application to execute remote procedures. One of the procedures is L ...

Continue Reading
SUSE SLED12 / SLES12 Security Update : php74 (SUSE-SU-2021:2636-1)

The remote SUSE Linux SLED12 / SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2021:2636-1 advisory. - Tenable.sc leverages third-party ...

Continue Reading
ruby:2.7 security update

ruby [2.7.4-137] - Upgrade to Ruby 2.7.4. - Fix command injection vulnerability in RDoc. Resolves: rhbz#1986768 - Fix FTP PASV command response can cause Net::FTP to connect to arbitrary host. Res ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

SUSE SLES15 Security Update : php7 (SUSE-SU-2021:2795-1)

The remote SUSE Linux SLES15 host has packages installed that are affected by a vulnerability as referenced in the SUSE- SU-2021:2795-1 advisory. - Tenable.sc leverages third-party software to help ...

Continue Reading
SUSE SLED12 / SLES12 Security Update : php72 (SUSE-SU-2021:2926-1)

The remote SUSE Linux SLED12 / SLES12 host has packages installed that are affected by a vulnerability as referenced in the SUSE-SU-2021:2926-1 advisory. - Tar.php in Archive_Tar through 1.4.11 allo ...

Continue Reading
EulerOS 2.0 SP2 : php (EulerOS-SA-2021-2423)

According to the versions of the php packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities : - When using the gdImageCreateFromXbm() function i ...

Continue Reading
(RHSA-2021:3559) Important: rh-ruby27-ruby security update

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. The following packages have been upgraded to a l ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

CVE-2021-37146

An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLR ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: