Garbage collection issue in BC-FJA in Java 13 and later

An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is p ...

Continue Reading
Security Bulletin: IBM DataPower Gateway potentially vulnerable to HTTP request smuggling

## Summary These flaws have the potential to affect the API Gateway Sservice. IBM has addressed the CVEs ## Vulnerability Details ** CVEID: **[CVE-2022-32213]() ** DESCRIPTION: **Node.js is vulnerable ...

Continue Reading

CVSS3 - CRITICAL

Tailscale Windows daemon is vulnerable to RCE via CSRF

A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. **Affected plat ...

Continue Reading
Tailscale daemon is vulnerable to information disclosure via CSRF

A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be used to access Tailscale environment variables. **Affected platforms:** All **Pa ...

Continue Reading
F5 BIG-IP iControl Cross Site Request Forgery Exploit

This Metasploit module exploits a cross-site request forgery (CSRF) vulnerability in F5 Big-IP's iControl interface to write an arbitrary file to the filesystem. While any file can be written to any l ...

Continue Reading
CVE-2022-37332

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory v ...

Continue Reading
CVE-2022-40129

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory v ...

Continue Reading
F5 Networks BIG-IP : iControl SOAP vulnerability (K94221585)

The version of F5 Networks BIG-IP installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the K94221585 advisory. Note that Nessus has n ...

Continue Reading

Back to Main

Subscribe for the latest news: