Alerts & Advisory dai CERTs

Gli ultimi avvisi di sicurezza dai Computer Emergency Response Teams governativi e non-governativi rilevanti del mondo cybersec

Mostrando 3376-3400 di 4595 risultati
Pagina 136 di 184

Avvisi di Sicurezza

CERT Alert Data #
MSRC Security UpdateCVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.15-04-20263376
MSRC Security UpdateCVE-2026-27139 FileInfo can escape from a Root in os15-04-20263377
MSRC Security UpdateCVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)15-04-20263378
MSRC Security UpdateCVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial15-04-20263379
MSRC Security UpdateCVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x50915-04-20263380
MSRC Security UpdateCVE-2026-33939 Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation15-04-20263381
MSRC Security UpdateCVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options15-04-20263382
MSRC Security UpdateCVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block15-04-20263383
MSRC Security UpdateCVE-2026-33891 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input15-04-20263384
MSRC Security UpdateCVE-2026-33896 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)15-04-20263385
MSRC Security UpdateCVE-2026-33895 Forge has signature forgery in Ed25519 due to missing S > L check15-04-20263386
MSRC Security UpdateCVE-2026-33671 Picomatch has a ReDoS vulnerability via extglob quantifiers15-04-20263387
MSRC Security UpdateCVE-2025-1220 Null byte termination in hostnames15-04-20263388
MSRC Security UpdateCVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation15-04-20263389
MSRC Security UpdateCVE-2026-33636 LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch6415-04-20263390
MSRC Security UpdateCVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`15-04-20263391
MSRC Security UpdateCVE-2025-30258 In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."15-04-20263392
MSRC Security UpdateCVE-2025-62718 Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF15-04-20263393
MSRC Security UpdateCVE-2026-40175 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain15-04-20263394
MSRC Security UpdateCVE-2026-34480 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters15-04-20263395
MSRC Security UpdateCVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters15-04-20263396
MSRC Security UpdateCVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout15-04-20263397
MSRC Security UpdateCVE-2026-35201 Discount has an Out-of-bounds Read in rdiscount15-04-20263398
MSRC Security UpdateCVE-2026-1502 HTTP client proxy tunnel headers not validated for CR/LF15-04-20263399
MSRC Security UpdateCVE-2026-5446 wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse15-04-20263400
Nessun risultato trovato

Prova a modificare i termini di ricerca

Le Fonti

Questa selezione di advisories è una lista ordinata per data di tutte le pubblicazioni dalle seguenti fonti:

US-CERT CISA
Twitter
Center of Internet Security
Twitter
FR-CERT Alertes
Twitter
FR-CERT Avis
Twitter
EU-ENISA Publications
Twitter
Google TAG
Microsoft Security
Unit42
Twitter
MSRC Security Update
Twitter
CERT-Bund DE
Twitter
CSIRT IT
Twitter
Consiglio Federale CH
Twitter