Alerts & Advisory dai CERTs

Gli ultimi avvisi di sicurezza dai Computer Emergency Response Teams governativi e non-governativi rilevanti del mondo cybersec

Mostrando 3601-3625 di 5670 risultati
Pagina 145 di 227

Avvisi di Sicurezza

CERT Alert Data #
MSRC Security UpdateCVE-2026-2297 SourcelessFileLoader does not use io.open_code()03-06-20263601
MSRC Security UpdateCVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh03-06-20263602
MSRC Security UpdateCVE-2026-6383 Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation03-06-20263603
MSRC Security UpdateCVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences03-06-20263604
MSRC Security UpdateCVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response03-06-20263605
MSRC Security UpdateCVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh03-06-20263606
MSRC Security UpdateCVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x50903-06-20263607
MSRC Security UpdateCVE-2026-37457 An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.03-06-20263608
MSRC Security UpdateCVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x50903-06-20263609
MSRC Security UpdateCVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service03-06-20263610
MSRC Security UpdateCVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions03-06-20263611
MSRC Security UpdateCVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html03-06-20263612
MSRC Security UpdateCVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).03-06-20263613
MSRC Security UpdateCVE-2025-9403 jqlang jq JSON jq_test.c run_jq_tests assertion03-06-20263614
MSRC Security UpdateCVE-2025-11083 GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow03-06-20263615
MSRC Security UpdateCVE-2026-6845 Binutils: binutils: denial of service via crafted elf file03-06-20263616
MSRC Security UpdateCVE-2025-61725 Excessive CPU consumption in ParseAddress in net/mail03-06-20263617
MSRC Security UpdateCVE-2025-58188 Panic when validating certificates with DSA public keys in crypto/x50903-06-20263618
MSRC Security UpdateCVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html03-06-20263619
MSRC Security UpdateCVE-2025-61724 Excessive CPU consumption in Reader.ReadResponse in net/textproto03-06-20263620
MSRC Security UpdateCVE-2025-58186 Lack of limit when parsing cookies can cause memory exhaustion in net/http03-06-20263621
MSRC Security UpdateCVE-2025-58183 Unbounded allocation when parsing GNU sparse map in archive/tar03-06-20263622
MSRC Security UpdateCVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization03-06-20263623
MSRC Security UpdateCVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs03-06-20263624
MSRC Security UpdateCVE-2026-40356 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.03-06-20263625
Nessun risultato trovato

Prova a modificare i termini di ricerca

Le Fonti

Questa selezione di advisories è una lista ordinata per data di tutte le pubblicazioni dalle seguenti fonti:

US-CERT CISA
Twitter
Center of Internet Security
Twitter
FR-CERT Alertes
Twitter
FR-CERT Avis
Twitter
EU-ENISA Publications
Twitter
Google TAG
Microsoft Security
Unit42
Twitter
MSRC Security Update
Twitter
CERT-Bund DE
Twitter
CSIRT IT
Twitter
Consiglio Federale CH
Twitter