Cap’n Proto and its Rust implementation vulnerable to out-of-bounds read due to logic error handling list-of-list

The Cap'n Proto library and capnp Rust package are vulnerable to out-of-bounds read due to logic error handling list-of-list. If a message consumer expects data of type "list of pointers", and if the ...

Continue Reading
CVE-2022-3907

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones s ...

Continue Reading
spacewalk-backend spacewalk-java security update

spacewalk-backend [2.10.28-1.0.13] - Fix HTTP 500 and ORA-01830 on client scap report [Orabug: 34823889] [2.10.28-1.0.12] - Handle remote commands that return no output. [Orabug: 32530545] [2.10.28-1. ...

Continue Reading
Security Bulletin: Rational Test Automation Server is vulnerable to incorrect authorization vulnerability due to Keycloak (CVE-2021-4133)

## Summary Keycloak vulnerability of incorrect authorization impacts Rational Test Automation Server. ## Vulnerability Details ** CVEID: **[CVE-2021-4133]() ** DESCRIPTION: **Keycloak could allow a re ...

Continue Reading
New BMC Supply Chain Vulnerabilities Affect Servers from Dozens of Manufacturers

[![](https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEiolCsXBH-kaR61fYu-jBJwv8qNy3L5XE48zgFzAOo0D8xZIhyZyPMESMC0L7Cy3993u4PbVASQyv9QyJAXwtP35mNPY_On_q3S9FJwsCvbkagdC6jHgRl1ax_y6XEyPDxf0fTYHuW ...

Continue Reading
Security Bulletin: IBM Spectrum Scale (GPFS) Hadoop connector is affected by a security vulnerability (CVE-2022-25168)

## Summary A security vulnerability has been identified in the IBM Spectrum Scale (GPFS) Hadoop connector which could allow a local authenticated attacker to execute arbitrary commands on the system. ...

Continue Reading
SiriusXM Vulnerability Lets Hackers Remotely Unlock and Start Connected Cars

[![Hack Connected Cars](https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEiJa01Keo3S1ObiTuCE6VQ0EqbIi7xwjsdV40blAZui0I0YEyNI5iiRWbg7TuJUhxyVqBI0QUPKKnQ32-4V7AxKyIT8Rjo20MEYa2Eqxtb8wy6rWOHgzAaq ...

Continue Reading
[SECURITY] [DLA 3222-1] node-fetch security update

------------------------------------------------------------------------- Debian LTS Advisory DLA-3222-1 [email protected] https://www.debian.org/lts/security/ ...

Continue Reading

Back to Main

Subscribe for the latest news: