CVE-2022-37797

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the ser ...

Continue Reading
Gohide – Tunnel Port To Port Traffic Over An Obfuscated Channel With AES-GCM Encryption

[![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHea8Qw-Qb_GsBYWzFYkzJuRajsskOY6vuS1azRXfGLfWXNtq0qqTLhNvCyvh6G15V3K0wqCwnUqcWvf6gVBzHUh1MBVFc9tvsGnh_UBpx7rnXMoV4_bQL_p04bYI_kkVBGLJ-sh ...

Continue Reading
RHEL 8 : RHV Manager (ovirt-engine) [ovirt-4.5.2] bug fix and (RHSA-2022:6393)

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2022:6393 advisory. - jquery: Cross-site scripting due to imp ...

Continue Reading
(RHSA-2022:6393) Important: RHV Manager (ovirt-engine) [ovirt-4.5.2] bug fix and security update

The ovirt-engine package provides the Red Hat Virtualization Manager, a centralized management platform that allows system administrators to view and manage virtual machines. The Manager provides a co ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Command Injection

tomcat6 is vulnerable to command injection. Apache Tomcat could allow a remote attacker to bypass security restrictions, caused by improper error handling in WebSocket connection. By sending a special ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Security Bulletin: IBM Rational Build Forge is affected by Apache Tomcat version used in it. (CVE-2021-42340)

## Summary IBM Rational Build Forge is affected by CVE-2021-42340. ## Vulnerability Details ** CVEID: **[CVE-2021-42340]() ** DESCRIPTION: **Apache Tomcat is vulnerable to a denial of service, caused ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: Watson Machine Learning Accelerator is affected but not classified as vulnerable by a remote code execution in Spring Framework (CVE-2022-22971)

## Summary Watson Machine Learning Accelerator is affected but not classified as vulnerable to a remote code execution in Spring Framework (CVE-2022-22971) as it does not meet all of the following cri ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security Bulletin: IBM UrbanCode Release is vulnerable to a denial of service due to use of Apache Tomcat CVE-2021-42340.

## Summary Apache Tomcat is used by IBM UrbanCode Release. This fix includes Apache Tomcat 8.5.79. ## Vulnerability Details ** CVEID: **[CVE-2021-42340]() ** DESCRIPTION: **Apache Tomcat is vulnerable ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: