Tag: privilegeEscalation

  • Topics Everyone Is Talking About No417

    Omarchy: Any User Process Can Escalate to Root • Claude Session URL appended to commit messages and PR descriptions by default • Europes summer drought is so extreme that desertification is a growing threat • Brits would quite like their private messages to stay private • Rust Function Overloading – Call for Experimentation…

  • Vulnerability Watch No61

    NLTK XML Parser Weakness Causes Denial of Service • node-poppler Flaw Allows Remote Argument Injection • Critical OCPP Buffer Overflow Threatens EV Charging Clients • WordPress InfusedWoo Pro Bug Enables Account Takeover • NLTK Deserialization Flaw Enables Python Code Execution…

  • Vulnerability Watch No60

    AWX Archive Extraction Path Traversal • HCL Hive Third-Party Component Vulnerability • GIMP PCX Plugin Memory Corruption Bug • rConfig Authentication Bypass Creates Admin Accounts • NetworkManager WPA-Enterprise Validation Flaw…

  • Vulnerability Watch No58

    LeafWiki Account Update Bug Enables Role Escalation • RaTeX Parser Crash Creates Denial of Service Risk • WordPress Plugin Flaw Enables Privilege Escalation • WeeChat Authentication Timing Bug Exposes Hashes • LeafWiki File Traversal Bug Can Expose Local Data…

  • Vulnerability Watch No56

    Splunk flaw lets lower-privileged users write arbitrary dispatch metadata • Splunk Monitoring Console link flaw enables unauthorized searches • Splunk authentication weakness can enable forged admin sessions • Splunk SPL2 API issue allows unauthorized module deletion • Splunk Web XML weakness enables operating system command execution…

  • Vulnerability Watch No55

    FFmpeg DASH Demuxer Vulnerable to Negative Array Index • FFmpeg AV1 RTP Packetizer Out-of-Bounds Read • FFmpeg VC-2 RTP Packetizer Heap Overflow • Critical FFmpeg RIST Reader Heap Buffer Overflow • FFmpeg MPEG-PS Muxer Stack Buffer Overflow…

  • Vulnerability Watch No54

    acmailer Authorization Flaw Enables Admin-Level Sub-Accounts • Atarim WordPress Plugin File Deletion Can Lead to RCE • TRENDnet Router Ping Interface Exposed to Command Injection • armeria-xds TLS Verification Flaw Enables MITM Attacks • TRENDnet TEW-823DRU Admin Endpoint Allows Command Injection…

  • Vulnerability Watch No53

    Kubernetes managed-serviceaccount flaw exposes cluster secrets • OpenSearch Dashboards request flaw enables remote denial of service • Dell PowerStore SDNAS NFS flaw can enable command execution • RabbitMQ Java client nesting bug triggers pre-authentication crashes • RabbitMQ Java client flaw enables massive pre-auth memory allocation…