Tag: memoryExhaustion

  • Vulnerability Watch No53

    Kubernetes managed-serviceaccount flaw exposes cluster secrets • OpenSearch Dashboards request flaw enables remote denial of service • Dell PowerStore SDNAS NFS flaw can enable command execution • RabbitMQ Java client nesting bug triggers pre-authentication crashes • RabbitMQ Java client flaw enables massive pre-auth memory allocation…

  • Vulnerability Watch No49

    Scriban Parser Recursion Can Crash Hosting Processes • Circular Objects Trigger Fatal Scriban Stack Exhaustion • Nested Arrays Bypass Scriban Expression Depth Protection • Scriban Template Cache Can Leak Previously Authorized Content • Scriban Cache Flaw Breaks MemberFilter Sandbox Boundaries…

  • Vulnerability Watch No39

    Windows DHCP Client Heap Overflow Enables Privilege Escalation • Browserslist Cache Exhaustion Can Crash Processes • Browserslist Stats Parsing Opens Door to Crashes and Prototype Changes • Nanoid Integer Bug Can Make Security Tokens Predictable • Windows CLFS Race Condition Enables Local Privilege Escalation…

  • Vulnerability Watch No33

    Bouncy Castle FIPS Key Zeroisation Can Fall Behind on Newer JVMs • Bouncy Castle FIPS Entropy Failure Can Hang Applications • Klever-Go REST APIs Exposed to Slow-Header Denial of Service • Klever-Go Peer Can Trigger Unbounded Goroutine Creation • Tiny Malformed Transaction Can Crash Klever-Go Nodes…

  • Vulnerability Watch No25

    Crafted Images Can Trigger GIMP Memory Corruption • Zyxel Firewall Path Traversal Enables Malicious Config Execution • Zyxel WAX650S Command Injection Exposes Device OS • Node.js HTTP2 Flaw Enables Remote Memory Exhaustion • CustomSounds Path Traversal Exposes Arbitrary Files…

  • Vulnerability Watch No24

    Brace Expansion Bypass Enables Memory Exhaustion • Angular i18n Flaw Turns Translations into JavaScript • Angular Server Rendering Exposes High-Severity XSS • Angular Cache-Key Collision Can Return the Wrong Data • OpenEMR OAuth Flow Bypasses Multi-Factor Authentication…

  • Vulnerability Watch No21

    Hardcoded Backdoor Exposes WordPress Sites to Admin Takeover • Easy Digital Downloads Upload Flaw Could Enable Code Execution • WooCommerce Wholesale Plugin Lets Authors Become Administrators • Netty OCSP Race Can Leak Data to Revoked Servers • Netty Accepts Replayed Expired OCSP Responses…

  • Vulnerability Watch No3

    Netty STOMP Header Flood Can Crash Servers • Hard-Coded Credentials Found in IBM Langflow OSS • IBM Langflow File Boundary Bypass Exposes User Data • Path Traversal Enables Arbitrary File Writes in Langflow • Langflow Privilege Escalation Can Fully Compromise Service…

  • Vulnerability Watch No1

    JLine Telnet Server Heap Exhaustion Flaw Hits Java Apps • Windows RDP Privacy Leak Exposes Private Information • HAPI FHIR Regex Bug Can Trigger Healthcare Service Outages • Avo Rails Framework Authorization Bypass Enables Data Exposure • ViewComponent XSS Flaw Risks Unsafe Rails Output…