Alerts & Advisory dai CERTs

Gli ultimi avvisi di sicurezza dai Computer Emergency Response Teams governativi e non-governativi rilevanti del mondo cybersec

Mostrando 3626-3650 di 5670 risultati
Pagina 146 di 227

Avvisi di Sicurezza

CERT Alert Data #
MSRC Security UpdateCVE-2025-55554 pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().03-06-20263626
MSRC Security UpdateCVE-2026-40355 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.03-06-20263627
MSRC Security UpdateCVE-2025-55551 An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.03-06-20263628
MSRC Security UpdateCVE-2026-39828 Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh03-06-20263629
MSRC Security UpdateCVE-2026-41526 In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.03-06-20263630
MSRC Security UpdateCVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerability03-06-20263631
MSRC Security UpdateCVE-2026-25541 Bytes is vulnerable to integer overflow in BytesMut::reserve03-06-20263632
MSRC Security UpdateCVE-2024-58266 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.03-06-20263633
MSRC Security UpdateCVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection03-06-20263634
MSRC Security UpdateCVE-2025-5791 Users: `root` appended to group listings03-06-20263635
MSRC Security UpdateCVE-2026-41607 Apache Thrift: C++ JSON OOB read03-06-20263636
MSRC Security UpdateCVE-2026-41606 Apache Thrift: c_glib dispatch stack overflow03-06-20263637
MSRC Security UpdateCVE-2025-1176 GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow03-06-20263638
MSRC Security UpdateCVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation03-06-20263639
MSRC Security UpdateCVE-2025-1178 GNU Binutils ld libbfd.c bfd_putl64 memory corruption03-06-20263640
MSRC Security UpdateCVE-2025-4574 Crossbeam-channel: crossbeam-channel vulnerable to double free on drop03-06-20263641
MSRC Security UpdateCVE-2025-3198 GNU Binutils objdump bucomm.c display_info memory leak03-06-20263642
MSRC Security UpdateCVE-2026-6238 Buffer overread in ns_printrrf with corrupted RDATA field03-06-20263643
MSRC Security UpdateCVE-2025-46327 Go Snowflake Driver has race condition when checking access to Easy Logging configuration file03-06-20263644
MSRC Security UpdateCVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address03-06-20263645
MSRC Security UpdateCVE-2025-46394 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.03-06-20263646
MSRC Security UpdateCVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects03-06-20263647
MSRC Security UpdateCVE-2024-58251 In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.03-06-20263648
MSRC Security UpdateCVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/103-06-20263649
MSRC Security UpdateCVE-2025-29923 go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment03-06-20263650
Nessun risultato trovato

Prova a modificare i termini di ricerca

Le Fonti

Questa selezione di advisories è una lista ordinata per data di tutte le pubblicazioni dalle seguenti fonti:

US-CERT CISA
Twitter
Center of Internet Security
Twitter
FR-CERT Alertes
Twitter
FR-CERT Avis
Twitter
EU-ENISA Publications
Twitter
Google TAG
Microsoft Security
Unit42
Twitter
MSRC Security Update
Twitter
CERT-Bund DE
Twitter
CSIRT IT
Twitter
Consiglio Federale CH
Twitter