17.03.2024 05:30 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the
17.03.2024 05:30 The updated packages fix security vulnerabilities: Server-Side Request Forgery vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. Server-Side Request Forgery vulnerability in Batik of Apache XML
16.03.2024 09:15 upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager
16.03.2024 09:15 Security fix for CVE-2007-4559.
16.03.2024 09:15 New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454
16.03.2024 09:15 Path traversal in moment.locale. Inefficient parsing algorithim resulting in DoS. References: - https://bugs.mageia.org/show_bug.cgi?id=30664
16.03.2024 09:15 Security fix for CVE-2007-4559.
16.03.2024 09:15 Update to 3.2.2 It indirectly fix CVE-2023-3966 and CVE-2023-5366
15.03.2024 23:01 Hatim Chabik discovered a cross-site scripting vulnerability in spip, a content management system, which can lead to privilege escalation or information disclosure.
15.03.2024 23:01 * bsc#1219836 Cross-References: * CVE-2024-1062
15.03.2024 23:01 It was discovered that composer, a dependency manager for the PHP language, processed files in the local working directory. This could lead to local privilege escalation or malicious code execution. Due to a technical issue this email was not sent on 2024-02-26 like it should
15.03.2024 23:01 * jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593
15.03.2024 23:01 * jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593
15.03.2024 23:01 * bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465
15.03.2024 12:31 The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config of llibmpcodecs/vf_scale.c. Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record of mplayer/libmpdemux/asfheader.c.