Ubuntu Security Notice 5529-1 - It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Yongkang Jia discovered that the KVM hypervisor implementation in the Linux kernel did not properly handle guest TLB mapping invalidation requests in some situations. An attacker in a guest VM could use this to cause a denial of service in the host OS.
900c9467490b73751623ae9022791a89235180da8de86cdb02eda9d2d8d16654
Chrome has an issue where raw_ptr broke implicit scoped_refptr for receivers in base::Bind.
608734695dfbbf56d37a25c6b0e92ec571e720ac20c50496dd9608c3ee36b587
Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) versions 1.31.460 and below suffer from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user via the name GET parameter in delsnap.pl Perl/CGI script which is used for deleting snapshots taken from the webcam.
d419b1daf53d0f565d05d6ba8ea75d7ee176ccb9140c55fa6180d7f9532dc155
CodoForum version 5.1 suffers from a remote code execution vulnerability.
045098f70a6461ea548965fba279c18d47668837e82112dbf85f351b43ee5baf
AIEngine is a packet inspection engine with capabilities of learning without any human intervention. It helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.
e51bc7defd4393939e716c60405cf72a4aa1c727b6ccde44784fd235022e5017
OctoBot WebInterface version 0.4.3 suffers from a remote code execution vulnerability.
e44b74ee9184e1f4fa497f4876744c69864ed4d789de8a18313422be9a4ad1c5
Kite version 1.2021.610.0 suffers from an unquoted service path vulnerability.
f6c26ab826fa44ce94b3128d1027703b3451aafa787d124ff97ae6903c5c30b1
Red Hat Security Advisory 2022-5673-01 - Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. Issues addressed include a code execution vulnerability.
e6a4b0b59b2757ea6ef380429f73c2819e182dbd4e1d06bf09b8c22eac8f952b
Dr. Fone version 4.0.8 suffers from an unquoted service path vulnerability.
a395c8c5023e9fa3ade5d03f2adda3d54bb86b40825eb131695b52008175f74a
IOTransfer version 4.0 suffers from a remote code execution vulnerability.
c710e2da6c6ed4ef7a63d1d4f9778557d2652281b2fc26cee33fa39fd5d1ca51
The Monroe Electronics / Digital Alert Systems OneNet SE DASDEC Emergency Alert System Appliance suffers from cross site scripting and html injection vulnerabilities.
82f6d98418853066b6a98235aa9b2f3a0913d729dcbf7cc7b1e70d395b6a8bad