Posted by Stefan Kanthak via Fulldisclosure on Sep 08
Hi @ll,Posted by Taylor Newsome on Sep 08
Reporter: [Taylor Christian Newsome / SleepRaps () gmail com]Posted by Taylor Newsome on Sep 08
*To:* support () mellanox com, networking-support () nvidia comPosted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 08
SEC Consult Vulnerability Lab Security Advisory < 20250908-0 >Posted by Ron E on Sep 08
An integer overflow vulnerability exists in the FFmpeg cache: URL protocolPosted by Ron E on Sep 08
A vulnerability exists in the FFmpeg UDP protocol implementation (Posted by Ron E on Sep 08
A signed integer overflow exists in FFmpegβs udp.c implementation whenPosted by Ron E on Sep 08
The ladspa audio filter implementation (libavfilter/af_ladspa.c) in FFmpegPosted by Ron E on Sep 08
Improper validation in libavutil/avstring.c allows a NULL pointerPosted by Ron E on Sep 08
FFmpeg invokes function pointers through incorrect type casting, leading toPosted by Ron E on Sep 08
The FFmpeg tools/yuvcmp utility is vulnerable to an integer overflow whenPosted by Ron E on Sep 08
Malformed .m3u8 playlists can trigger a heap use-after-free when the HLSPosted by Ron E on Sep 08
The DjVuLibre document compression library (tested version 3.5.29) containsPosted by Ron E on Sep 08
The DjVuLibre document compression library (tested version 3.5.29) isPosted by Ron E on Sep 08
An integer overflow vulnerability exists in the Y4M input loader (loadY4MPosted by Ron E on Sep 08
During construction of a Track_Visual object, corrupted sequence metadataPosted by Ron E on Sep 08
Box_hdlr::get_handler_type() (libheif/box.h:487) is called even when thePosted by Ron E on Sep 08
The FullBox::get_flags() method retrieves 24-bit flags from the underlyingPosted by Ron E on Sep 08
The Box_stts structure defines decoding time to sample mapping. InPosted by Ron E on Sep 08
The Track::init_sample_timing_table logic manages aPosted by Ron E on Sep 08
The vulnerability resides in the constructor Chunk::Chunk (Posted by Seralys Research Team via Fulldisclosure on Sep 08
Seralys Security Advisory | https://www.seralys.com/researchPosted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-5 macOS Ventura 13.7.8Posted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-4 macOS Sonoma 14.7.8Posted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-3 macOS Sequoia 15.6.1Posted by Apple Product Security via Fulldisclosure on Sep 08
APPLE-SA-08-20-2025-2 iPadOS 17.7.10Posted by Asterisk Development Team via Fulldisclosure on Sep 08
The Asterisk Development Team would like to announce security releasePosted by Asterisk Development Team via Fulldisclosure on Sep 08
The Asterisk Development Team would like to announce security releasePosted by Asterisk Development Team via Fulldisclosure on Sep 08
The Asterisk Development Team would like to announce security releasePosted by Joseph Goydish II via Fulldisclosure on Sep 08
TITLE:Posted by Usman Saeed via Fulldisclosure on Aug 18
#!/usr/bin/env python3Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Aug 18
Confidentiality class: Internal & PartnerPosted by SEC Consult Vulnerability Lab via Fulldisclosure on Aug 18
Confidentiality class: Internal & PartnerPosted by Ron E on Aug 18
nopCommerce is vulnerable to Insufficient Resource Allocation Limits whenPosted by Ron E on Aug 18
nopCommerce versions v4.10 and v4.80.3 are vulnerable to *C*SV InjectionPosted by Ron E on Aug 18
nopCommerce v4.10 and 4.80.3 is vulnerable to Insufficient Invalidation ofPosted by Ron E on Aug 18
The application does not issue a new session identifier (JSESSIONID) afterPosted by Ron E on Aug 18
A CSV Injection vulnerability exists in iDempiere WebUIPosted by Ron E on Aug 18
lcf2xml (part of liblcf) aborts when parsing specially crafted RPG MakerPosted by Ron E on Aug 18
A crafted RPG Maker save file (`.lsd`) can trigger an integer overflow inPosted by Georg Lukas on Aug 18
<PDF advisory:Posted by Georg Lukas on Aug 18
PDF advisory: https://rt-solutions.de/piciorgros/Piciorgros_TMO-100_IP-Logger_en.pdfPosted by Jozef Sudolsky on Aug 18
Dear community,Posted by josephgoyd via Fulldisclosure on Aug 18
TITLE: Undocumented TCC Access to Multiple Privacy Domains via 'preflight=yes' in iOS 18.6Posted by Security Explorations on Aug 12
Dear All,Posted by Security Explorations on Aug 12
Dear All,Posted by Stefan Kanthak via Fulldisclosure on Aug 04
Hi @ll,Posted by Sandro Gauci via Fulldisclosure on Aug 02
Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration (CVSS v4.0 Score: 9.3 / Critical)Posted by Apple Product Security via Fulldisclosure on Aug 02
APPLE-SA-07-30-2025-1 Safari 18.6Posted by Stefan Kanthak via Fulldisclosure on Jul 29
Hi @ll,Posted by Thomas Weber | CyberDanube via Fulldisclosure on Jul 29
St. PΓΆlten UAS 20250721-0Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-8 visionOS 2.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-7 tvOS 18.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-6 watchOS 11.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-5 macOS Ventura 13.7.7Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-4 macOS Sonoma 14.7.7Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-3 macOS Sequoia 15.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-2 iPadOS 17.7.9Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-1 iOS 18.6 and iPadOS 18.6Posted by Egidio Romano on Jul 29
----------------------------------------------------------------------------