Alerts & Advisory dai CERTs

Gli ultimi avvisi di sicurezza dai Computer Emergency Response Teams governativi e non-governativi rilevanti del mondo cybersec

Mostrando 3676-3700 di 5670 risultati
Pagina 148 di 227

Avvisi di Sicurezza

CERT Alert Data #
MSRC Security UpdateCVE-2019-11254 Kubernetes API Server denial of service vulnerability from malicious YAML payloads03-06-20263676
MSRC Security UpdateCVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()03-06-20263677
MSRC Security UpdateCVE-2026-6253 proxy credentials leak over redirect-to proxy03-06-20263678
MSRC Security UpdateCVE-2013-1633 easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.03-06-20263679
MSRC Security UpdateCVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure03-06-20263680
MSRC Security UpdateCVE-2023-1386 Qemu: 9pfs: suid/sgid bits not dropped on file write03-06-20263681
MSRC Security UpdateCVE-2026-1502 HTTP client proxy tunnel headers not validated for CR/LF03-06-20263682
MSRC Security UpdateCVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.03-06-20263683
MSRC Security UpdateCVE-2020-8561 Webhook redirect in kube-apiserver03-06-20263684
MSRC Security UpdateCVE-2021-25740 Holes in EndpointSlice Validation Enable Host Network Hijack03-06-20263685
MSRC Security UpdateCVE-2026-40361 Microsoft Outlook and Word Remote Code Execution Vulnerability02-06-20263686
MSRC Security UpdateCVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UI02-06-20263687
MSRC Security UpdateCVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date02-06-20263688
MSRC Security UpdateCVE-2026-28387 Potential Use-after-free in DANE Client Code02-06-20263689
MSRC Security UpdateCVE-2026-25833 Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function02-06-20263690
MSRC Security UpdateCVE-2026-25834 Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.02-06-20263691
MSRC Security UpdateCVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL02-06-20263692
MSRC Security UpdateCVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.02-06-20263693
MSRC Security UpdateCVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.02-06-20263694
MSRC Security UpdateCVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference02-06-20263695
MSRC Security UpdateCVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group02-06-20263696
MSRC Security UpdateCVE-2026-34875 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.02-06-20263697
MSRC Security UpdateCVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).02-06-20263698
MSRC Security UpdateCVE-2026-21711 A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature.02-06-20263699
MSRC Security UpdateCVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo02-06-20263700
Nessun risultato trovato

Prova a modificare i termini di ricerca

Le Fonti

Questa selezione di advisories è una lista ordinata per data di tutte le pubblicazioni dalle seguenti fonti:

US-CERT CISA
Twitter
Center of Internet Security
Twitter
FR-CERT Alertes
Twitter
FR-CERT Avis
Twitter
EU-ENISA Publications
Twitter
Google TAG
Microsoft Security
Unit42
Twitter
MSRC Security Update
Twitter
CERT-Bund DE
Twitter
CSIRT IT
Twitter
Consiglio Federale CH
Twitter