Alerts & Advisory dai CERTs

Gli ultimi avvisi di sicurezza dai Computer Emergency Response Teams governativi e non-governativi rilevanti del mondo cybersec

Mostrando 1976-2000 di 3706 risultati
Pagina 80 di 149

Avvisi di Sicurezza

CERT Alert Data #
MSRC Security UpdateCVE-2025-38251 atm: clip: prevent NULL deref in clip_push()18-02-20261976
MSRC Security UpdateCVE-2020-36475 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.18-02-20261977
MSRC Security UpdateCVE-2025-21683 bpf: Fix bpf_sk_select_reuseport() memory leak18-02-20261978
MSRC Security UpdateCVE-2024-0874 Coredns: cd bit response is cached and served later18-02-20261979
MSRC Security UpdateCVE-2024-50615 TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.18-02-20261980
MSRC Security UpdateCVE-2025-38263 bcache: fix NULL pointer in cache_set_flush()18-02-20261981
MSRC Security UpdateCVE-2020-36477 An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though).18-02-20261982
MSRC Security UpdateCVE-2023-6816 Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer18-02-20261983
MSRC Security UpdateCVE-2025-21665 filemap: avoid truncating 64-bit offset to 32 bits18-02-20261984
MSRC Security UpdateCVE-2023-28154 Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.18-02-20261985
MSRC Security UpdateCVE-2024-49761 REXML ReDoS vulnerability18-02-20261986
MSRC Security UpdateCVE-2024-42081 drm/xe/xe_devcoredump: Check NULL before assignments18-02-20261987
MSRC Security UpdateCVE-2025-38259 ASoC: codecs: wcd9335: Fix missing free of regulator supplies18-02-20261988
MSRC Security UpdateCVE-2025-37944 wifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process18-02-20261989
MSRC Security UpdateCVE-2010-0291 The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."18-02-20261990
MSRC Security UpdateCVE-2011-4969 Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.18-02-20261991
MSRC Security UpdateCVE-2024-0408 Xorg-x11-server: selinux unlabeled glx pbuffer18-02-20261992
MSRC Security UpdateCVE-2022-33103 Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().18-02-20261993
MSRC Security UpdateCVE-2023-45283 Insecure parsing of Windows paths with a \??\ prefix in path/filepath18-02-20261994
MSRC Security UpdateCVE-2025-37943 wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi18-02-20261995
MSRC Security UpdateCVE-2024-42078 nfsd: initialise nfsd_info.mutex early.18-02-20261996
MSRC Security UpdateCVE-2025-38249 ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3()18-02-20261997
MSRC Security UpdateCVE-2025-21631 block, bfq: fix waker_bfqq UAF after bfq_split_bfqq()18-02-20261998
MSRC Security UpdateCVE-2025-37757 tipc: fix memory leak in tipc_link_xmit18-02-20261999
MSRC Security UpdateCVE-2024-0409 Xorg-x11-server: selinux context corruption18-02-20262000
Nessun risultato trovato

Prova a modificare i termini di ricerca

Le Fonti

Questa selezione di advisories è una lista ordinata per data di tutte le pubblicazioni dalle seguenti fonti:

US-CERT CISA
Twitter
Center of Internet Security
Twitter
FR-CERT Alertes
Twitter
FR-CERT Avis
Twitter
EU-ENISA Publications
Twitter
Google TAG
Microsoft Security
Unit42
Twitter
MSRC Security Update
Twitter
CERT-Bund DE
Twitter
CSIRT IT
Twitter
Consiglio Federale CH
Twitter