Amazon Linux 2 : edk2 (ALAS-2024-2591)

It is, therefore, affected by a vulnerability as referenced in the ALAS2-2024-2591 advisory. Issue summary: Calling the OpenSSL API function SSL_select_next_proto with anempty supported client pro ...

Continue Reading
Chinese Hackers Target Taiwan and US NGO with MgBot Malware

Organizations in Taiwan and a U.S. non-governmental organization (NGO) based in China have been targeted by a Beijing-affiliated state-sponsored hacking group called Daggerfly using an upgraded set of ...

Continue Reading
Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal – Remote Code Execution

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this...Read More ...

Continue Reading
Photon OS 3.0: Linux PHSA-2021-3.0-0193

An update of the linux package has been...Read More ...

Continue Reading
CVE-2024-39902

Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8, the ch ...

Continue Reading
CVE-2024-41131

ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentia ...

Continue Reading
CVE-2024-41132

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulner ...

Continue Reading
CVE-2024-40634

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large ...

Continue Reading

Back to Main

Subscribe for the latest news: