RHEL 8 : thunderbird (RHSA-2024:0959)

The remote Redhat Enterprise Linux 8 host has a package installed that is affected by multiple vulnerabilities as referenced in the RHSA-2024:0959 advisory. When storing and re-accessing data on a n ...

Continue Reading
Oracle Linux 7 : thunderbird (ELSA-2024-0957)

The remote Oracle Linux 7 host has a package installed that is affected by multiple vulnerabilities as referenced in the ELSA-2024-0957 advisory. A website could have obscured the fullscreen notific ...

Continue Reading
Oracle Linux 7 : firefox (ELSA-2024-0976)

The remote Oracle Linux 7 host has a package installed that is affected by multiple vulnerabilities as referenced in the ELSA-2024-0976 advisory. Through a series of API calls and redirects, an atta ...

Continue Reading
Oracle Linux 8 : firefox (ELSA-2024-0955)

The remote Oracle Linux 8 host has a package installed that is affected by multiple vulnerabilities as referenced in the ELSA-2024-0955 advisory. Incorrect code generation could have led to unexpect ...

Continue Reading
RHEL 9 : firefox (RHSA-2024:0983)

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2024:0983 advisory. When storing and re-accessing data on a n ...

Continue Reading
Kirby vulnerable to self cross-site scripting (self-XSS) in the URL field

TL;DR This vulnerability affects Kirby sites that use the URL field in any blueprint. A successful attack commonly requires knowledge of the content structure by the attacker as well as social enginee ...

Continue Reading
Kirby vulnerable to Cross-site scripting (XSS) in the link field “Custom” type

TL;DR This vulnerability affects Kirby sites that use the new link field and output the entered link without additional validation or sanitization. The attack commonly requires user interaction by ano ...

Continue Reading
Minder trusts client-provided mapping from repo name to upstream ID

Summary When using a modified client or the grpc interface directly, the RegisterRepository call accepts both the repository owner / repo and the repo_id. Furthermore, these two are not checked for m ...

Continue Reading

Back to Main

Subscribe for the latest news: