Alerts & Advisory dai CERTs

Gli ultimi avvisi di sicurezza dai Computer Emergency Response Teams governativi e non-governativi rilevanti del mondo cybersec

Mostrando 4551-4575 di 5670 risultati
Pagina 183 di 227

Avvisi di Sicurezza

CERT Alert Data #
MSRC Security UpdateCVE-2025-66442 In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.19-05-20264551
MSRC Security UpdateCVE-2026-42011 Gnutls: gnutls: security bypass due to incorrect name constraint handling19-05-20264552
MSRC Security UpdateCVE-2026-25835 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).19-05-20264553
MSRC Security UpdateCVE-2026-34876 An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.19-05-20264554
MSRC Security UpdateCVE-2026-4892 CVE-2026-489219-05-20264555
MSRC Security UpdateCVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.19-05-20264556
MSRC Security UpdateCVE-2026-8295 Integer overflow in simdjson19-05-20264557
MSRC Security UpdateCVE-2026-5773 wrong reuse of SMB connection19-05-20264558
MSRC Security UpdateCVE-2026-7168 cross-proxy Digest auth state leak19-05-20264559
MSRC Security UpdateCVE-2026-6253 proxy credentials leak over redirect-to proxy19-05-20264560
MSRC Security UpdateCVE-2026-3833 Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison19-05-20264561
MSRC Security UpdateCVE-2026-6429 netrc credential leak with reused proxy connection19-05-20264562
MSRC Security UpdateCVE-2026-43267 wifi: rtw89: fix potential zero beacon interval in beacon tracking19-05-20264563
MSRC Security UpdateCVE-2026-43228 hfs: Replace BUG_ON with error handling for CNID count checks19-05-20264564
MSRC Security UpdateCVE-2026-4873 connection reuse ignores TLS requirement19-05-20264565
MSRC Security UpdateCVE-2026-43213 wifi: rtw89: pci: validate sequence number of TX release report19-05-20264566
MSRC Security UpdateCVE-2025-71272 most: core: fix resource leak in most_register_interface error paths19-05-20264567
MSRC Security UpdateCVE-2026-43219 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet19-05-20264568
MSRC Security UpdateCVE-2026-6276 stale custom cookie host causes cookie leak19-05-20264569
MSRC Security UpdateCVE-2026-43185 ksmbd: fix signededness bug in smb_direct_prepare_negotiation()19-05-20264570
MSRC Security UpdateCVE-2026-43115 srcu: Use irq_work to start GP in tiny SRCU19-05-20264571
MSRC Security UpdateCVE-2026-43126 ALSA: mixer: oss: Add card disconnect checkpoints19-05-20264572
MSRC Security UpdateCVE-2026-43204 ASoC: qcom: q6asm: drop DSP responses for closed data streams19-05-20264573
MSRC Security UpdateCVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash19-05-20264574
MSRC Security UpdateCVE-2026-43176 wifi: rtw89: pci: validate release report content before using for RTL8922DE19-05-20264575
Nessun risultato trovato

Prova a modificare i termini di ricerca

Le Fonti

Questa selezione di advisories è una lista ordinata per data di tutte le pubblicazioni dalle seguenti fonti:

US-CERT CISA
Twitter
Center of Internet Security
Twitter
FR-CERT Alertes
Twitter
FR-CERT Avis
Twitter
EU-ENISA Publications
Twitter
Google TAG
Microsoft Security
Unit42
Twitter
MSRC Security Update
Twitter
CERT-Bund DE
Twitter
CSIRT IT
Twitter
Consiglio Federale CH
Twitter