Posted by Stefan Kanthak via Fulldisclosure on Sep 08
Hi @ll,Posted by Taylor Newsome on Sep 08
Reporter: [Taylor Christian Newsome / SleepRaps () gmail com]Posted by Taylor Newsome on Sep 08
*To:* support () mellanox com, networking-support () nvidia comPosted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 08
SEC Consult Vulnerability Lab Security Advisory < 20250908-0 >Posted by Ron E on Sep 08
An integer overflow vulnerability exists in the FFmpeg cache: URL protocolPosted by Ron E on Sep 08
A vulnerability exists in the FFmpeg UDP protocol implementation (Posted by Ron E on Sep 08
A signed integer overflow exists in FFmpegβs udp.c implementation whenPosted by Ron E on Sep 08
The ladspa audio filter implementation (libavfilter/af_ladspa.c) in FFmpegPosted by Ron E on Sep 08
Improper validation in libavutil/avstring.c allows a NULL pointerPosted by Ron E on Sep 08
FFmpeg invokes function pointers through incorrect type casting, leading toPosted by Ron E on Sep 08
The FFmpeg tools/yuvcmp utility is vulnerable to an integer overflow whenPosted by Ron E on Sep 08
Malformed .m3u8 playlists can trigger a heap use-after-free when the HLSPosted by Ron E on Sep 08
The DjVuLibre document compression library (tested version 3.5.29) containsPosted by Ron E on Sep 08
The DjVuLibre document compression library (tested version 3.5.29) isPosted by Ron E on Sep 08
An integer overflow vulnerability exists in the Y4M input loader (loadY4MPosted by Ron E on Sep 08
During construction of a Track_Visual object, corrupted sequence metadataPosted by Ron E on Sep 08
Box_hdlr::get_handler_type() (libheif/box.h:487) is called even when thePosted by Ron E on Sep 08
The FullBox::get_flags() method retrieves 24-bit flags from the underlyingPosted by Ron E on Sep 08
The Box_stts structure defines decoding time to sample mapping. InPosted by Ron E on Sep 08
The Track::init_sample_timing_table logic manages aPosted by Ron E on Sep 08
The vulnerability resides in the constructor Chunk::Chunk (Posted by Seralys Research Team via Fulldisclosure on Sep 08
Seralys Security Advisory | https://www.seralys.com/researchPosted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-5 macOS Ventura 13.7.8Posted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-4 macOS Sonoma 14.7.8Posted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-3 macOS Sequoia 15.6.1Posted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-2 iPadOS 17.7.10Posted by Asterisk Development Team via Fulldisclosure on Sep 08
The Asterisk Development Team would like to announce security releasePosted by Asterisk Development Team via Fulldisclosure on Sep 08
The Asterisk Development Team would like to announce security releasePosted by Asterisk Development Team via Fulldisclosure on Sep 08
The Asterisk Development Team would like to announce security releasePosted by Joseph Goydish II via Fulldisclosure on Sep 08
TITLE:Posted by Usman Saeed via Fulldisclosure on Aug 18
#!/usr/bin/env python3Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Aug 18
Confidentiality class: Internal & PartnerPosted by SEC Consult Vulnerability Lab via Fulldisclosure on Aug 18
Confidentiality class: Internal & PartnerPosted by Ron E on Aug 18
nopCommerce is vulnerable to Insufficient Resource Allocation Limits whenPosted by Ron E on Aug 18
nopCommerce versions v4.10 and v4.80.3 are vulnerable to *C*SV InjectionPosted by Ron E on Aug 18
nopCommerce v4.10 and 4.80.3 is vulnerable to Insufficient Invalidation ofPosted by Ron E on Aug 18
The application does not issue a new session identifier (JSESSIONID) afterPosted by Ron E on Aug 18
A CSV Injection vulnerability exists in iDempiere WebUIPosted by Ron E on Aug 18
lcf2xml (part of liblcf) aborts when parsing specially crafted RPG MakerPosted by Ron E on Aug 18
A crafted RPG Maker save file (`.lsd`) can trigger an integer overflow inPosted by Georg Lukas on Aug 18
<PDF advisory:Posted by Georg Lukas on Aug 18
PDF advisory: https://rt-solutions.de/piciorgros/Piciorgros_TMO-100_IP-Logger_en.pdfPosted by Jozef Sudolsky on Aug 18
Dear community,Posted by josephgoyd via Fulldisclosure on Aug 18
TITLE: Undocumented TCC Access to Multiple Privacy Domains via 'preflight=yes' in iOS 18.6Posted by Security Explorations on Aug 12
Dear All,Posted by Security Explorations on Aug 12
Dear All,