Messages by Date
-
2024/11/06
Re: [oss-security] shell wildcard expansion (un)safety
David A. Wheeler
-
2024/11/05
[oss-security] [SECURITY ADVISTORY] curl: CVE-2024-9681 HSTS subdomain overwrites parent cache entry
Daniel Stenberg
-
2024/11/05
[oss-security] shell wildcard expansion (un)safety
Solar Designer
-
2024/11/03
[oss-security] CVE-2024-23590: Apache Kylin: Session fixation in web interface
Li Yang
-
2024/11/01
Re: [oss-security] mpg123 buffer overflow in versions before 1.32.8 (Frankenstein's Monster)
Dr. Thomas Orgis
-
2024/11/01
Re: [oss-security] mpg123 buffer overflow in versions before 1.32.8 (Frankenstein's Monster)
Dr. Thomas Orgis
-
2024/10/31
Re: [oss-security] mpg123 buffer overflow in versions before 1.32.8 (Frankenstein's Monster)
Alexander Patrakov
-
2024/10/31
Re: [oss-security] mpg123 buffer overflow in versions before 1.32.8 (Frankenstein's Monster)
Marco Benatto
-
2024/10/30
[oss-security] Re: qBittorrent RCE, Browser Hijacking vulnerabilities
Eli Schwartz
-
2024/10/30
[oss-security] CVE-2024-43383: Apache Lucene.Net.Replicator: Remote Code Execution in Lucene.Net.Replicator
Paul Irwin
-
2024/10/30
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2024-0006
Adrian Perez de Castro
-
2024/10/30
Re: [oss-security] mpg123 buffer overflow in versions before 1.32.8 (Frankenstein's Monster)
Marco Benatto
-
2024/10/30
[oss-security] qBittorrent RCE, Browser Hijacking vulnerabilities
Sec Guy
-
2024/10/30
[oss-security] mpg123 buffer overflow in versions before 1.32.8 (Frankenstein's Monster)
Dr. Thomas Orgis
-
2024/10/29
Re: [oss-security] CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets
Jacob Bachmeyer
-
2024/10/29
[oss-security] CVE-2024-9632: X.Org X server and Xwayland: Heap-based buffer overflow privilege escalation in _XkbSetCompatMap
Jose Exposito Quintana
-
2024/10/29
[oss-security] CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets
Joel GUITTET
-
2024/10/28
[oss-security] CVE-2024-45477: Apache NiFi: Improper Neutralization of Input in Parameter Description
David Handermann
-
2024/10/24
[oss-security] CVE-2024-9050: NetworkManager-libreswan IPSec VPN plugin local code execution
Lubomir Rintel
-
2024/10/24
[oss-security] CVE-2024-45031: Apache Syncope: Stored XSS in Console and Enduser
Francesco Chicchiriccò
-
2024/10/24
Re: [oss-security] CVE-2024-9143: OpenSSL: Low-level invalid GF(2^m) parameters lead to OOB memory access
Dr. Christopher Kunz
-
2024/10/23
Re: [oss-security] CVE-2024-9143: OpenSSL: Low-level invalid GF(2^m) parameters lead to OOB memory access
Dr. Christopher Kunz
-
2024/10/17
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Solar Designer
-
2024/10/17
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Steffen Nurpmeso
-
2024/10/17
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Matthias Gerstner
-
2024/10/16
[oss-security] CVE-2024-9143: OpenSSL: Low-level invalid GF(2^m) parameters lead to OOB memory access
Tomas Mraz
-
2024/10/15
[oss-security] CVE-2024-45217: Apache Solr: ConfigSets created during a backup restore command are trusted implicitly
Houston Putman
-
2024/10/15
[oss-security] CVE-2024-45216: Apache Solr: Authentication bypass possible using a fake URL Path ending
Houston Putman
-
2024/10/15
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Solar Designer
-
2024/10/15
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Demi Marie Obenour
-
2024/10/15
[oss-security] CVE-2024-45693: Apache CloudStack: Request origin validation bypass makes account takeover possible
Daniel Augusto Veronezi Salvador
-
2024/10/15
[oss-security] CVE-2024-45462: Apache CloudStack: Incomplete session invalidation on web interface logout
Daniel Augusto Veronezi Salvador
-
2024/10/15
[oss-security] CVE-2024-45461: Apache CloudStack Quota plugin: Access checks not enforced in Quota
Daniel Augusto Veronezi Salvador
-
2024/10/15
[oss-security] CVE-2024-45219: Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure
Daniel Augusto Veronezi Salvador
-
2024/10/15
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Matthias Gerstner
-
2024/10/14
[oss-security] CVE-2023-50780: Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
Justin Bertram
-
2024/10/14
[oss-security] [kubernetes] CVE-2024-9486 and CVE-2024-9594: VM images built with Kubernetes Image Builder use default credentials
Joel Smith
-
2024/10/11
[oss-security] CVE-2024-46911: Apache Roller: Weakness in CSRF protection allows privilege escalation
David M. Johnson
-
2024/10/10
[oss-security] libarchive 3.7.5 released with security fixes
Alan Coopersmith
-
2024/10/09
[oss-security] CVE-2024-28168: Apache XML Graphics FOP: XML External Entity (XXE) Processing
Simon Steiner
-
2024/10/08
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Solar Designer
-
2024/10/08
[oss-security] CVE-2024-45720: Apache Subversion: Command line argument injection on Windows platforms
Stefan Sperling
-
2024/10/08
[oss-security] Re: CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Simon Josefsson
-
2024/10/07
Re: [oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Solar Designer
-
2024/10/06
[oss-security] [vim-security] use-after-free when closing buffers in Vim < 9.1.0764
Christian Brabandt
-
2024/10/05
[oss-security] OSSA-2024-004 / CVE-2024-47211: OpenStack Ironic <26.1.1 fails to verify checksums of supplied image_source URLs when configured to convert images to raw for streaming
Jay Faulkner
-
2024/10/05
[oss-security] Re: CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Simon Josefsson
-
2024/10/04
[oss-security] CVE-2024-8508 in Unbound DNS server prior to 1.21.1
Alan Coopersmith
-
2024/10/04
Re: [oss-security] CVE-2024-42415: Integer Overflow in GNOME libgsf
Alan Coopersmith
-
2024/10/04
[oss-security] CVE-2024-42415: Integer Overflow in GNOME libgsf
Alan Coopersmith
-
2024/10/04
[oss-security] CVE-2024-47191: Local root exploit in the PAM module pam_oath.so
Johannes Segitz
-
2024/10/04
Re[2]: [oss-security] cups-browsed vulnerable to DDoS amplification attack
larry0
-
2024/10/03
Re: [oss-security] cups-browsed vulnerable to DDoS amplification attack
Larry Cashdollar
-
2024/10/03
Re: [oss-security] cups-browsed vulnerable to DDoS amplification attack
Peter van Dijk
-
2024/10/03
[oss-security] cups-browsed vulnerable to DDoS amplification attack
Larry Cashdollar
-
2024/10/03
[oss-security] PowerDNS Security Advisory 2024-04
Otto Moerbeek
-
2024/10/03
[oss-security] CVE-2024-47554: Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Gary D. Gregory
-
2024/10/03
[oss-security] CVE-2024-47561: Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
Martin Tzvetanov Grigorov
-
2024/10/02
[oss-security] Multiple vulnerabilities in Jenkins and Jenkins plugins
Daniel Beck
-
2024/09/28
[oss-security] CVE-2024-45772: Apache Lucene Replicator: Deserialization of Untrusted Data
Robert Muir
-
2024/09/27
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Sam Bull
-
2024/09/27
Re: [oss-security] List linux CVEs for a given stable release?
Greg Kroah-Hartman
-
2024/09/27
Re: [oss-security] CUPS printing system vulnerabilities
Will Dormann
-
2024/09/27
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Fabian Bäumer
-
2024/09/27
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Alexander Patrakov
-
2024/09/26
Re: [oss-security] CUPS printing system vulnerabilities
Michael Sweet
-
2024/09/26
Re: [oss-security] CUPS printing system vulnerabilities
Mark Esler
-
2024/09/26
Re: [oss-security] CUPS printing system vulnerabilities
Zdenek Dohnal
-
2024/09/26
Re: [oss-security] CUPS printing system vulnerabilities
Solar Designer
-
2024/09/26
Re: [oss-security] CUPS printing system vulnerabilities
Alan Coopersmith
-
2024/09/26
[oss-security] CUPS printing system vulnerabilities
Solar Designer
-
2024/09/26
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Solar Designer
-
2024/09/26
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Fabian Bäumer
-
2024/09/26
[oss-security] CVE-2024-47197: Maven Archetype Plugin: Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentials
Slawomir Jaranowski
-
2024/09/26
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
LinkinStar
-
2024/09/25
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Jeffrey Walton
-
2024/09/25
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Demi Marie Obenour
-
2024/09/25
RE: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Goldberg, Adam
-
2024/09/25
Re: [oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Solar Designer
-
2024/09/25
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2024-0005
Adrian Perez de Castro
-
2024/09/25
Re: [oss-security] CVE-2024-42154: Linux kernel: tcp_metrics: validate source addr length
Sandipan Roy
-
2024/09/25
[oss-security] CVE-2024-40761: Apache Answer: Avatar URL leaked user email addresses
Enxin Xie
-
2024/09/24
[oss-security] CVE-2024-23454: Apache Hadoop: Temporary File Local Information Disclosure
Shilun Fan
-
2024/09/24
Re: [oss-security] CVE-2024-42154: Linux kernel: tcp_metrics: validate source addr length
Solar Designer
-
2024/09/24
[oss-security] CVE-2024-42154: Linux kernel: tcp_metrics: validate source addr length
Joel GUITTET
-
2024/09/24
[oss-security] CVE-2024-39928: Apache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerability
Heping Wang
-
2024/09/24
[oss-security] Xen Security Advisory 462 v2 (CVE-2024-45817) - x86: Deadlock in vlapic_error()
Xen . org security team
-
2024/09/23
[oss-security] CVE-2024-38286: Apache Tomcat: Denial of Service
Mark Thomas
-
2024/09/23
[oss-security] CVE-2024-46544: Apache Tomcat Connectors: mod_jk: local users can view and modify configuration
Mark Thomas
-
2024/09/21
[oss-security] CVE-2024-42323: Apache HertzBeat: RCE by snakeYaml deser load malicious xml
Chao Gong
-
2024/09/20
[oss-security] Performance Co-Pilot (PCP): pmcd network daemon security issues and review results (CVE-2024-45769), (CVE-2024-45770)
Matthias Gerstner
-
2024/09/17
[oss-security] CVE-2024-45537: Apache Druid: Users can provide MySQL JDBC properties not on allow list
Karan Kumar
-
2024/09/17
[oss-security] CVE-2024-45384: Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack
Karan Kumar
-
2024/09/11
[oss-security] CVE-2024-22399: Apache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server
Min Ji
-
2024/09/10
[oss-security] [SECURITY ADVISORY] curl: CVE-2024-8096: OCSP stapling bypass with GnuTLS
Daniel Stenberg
-
2024/09/09
[oss-security] CVE-2024-6655 Library injection from CWD in GTK-2/GTK-3
Dimitrios Glynos
-
2024/09/07
[oss-security] Security fixes available in Python 3.13.0RC2, 3.12.6, 3.11.10, 3.10.15, 3.9.20, and 3.8.20
Alan Coopersmith
-
2024/09/07
[oss-security] CVE-2024-45751: CHAP authentication bypass in user-space Linux target framework (tgt) up to v1.0.92
David Gstir
-
2024/09/06
[oss-security] libpcap 1.10.5 released with two security fixes
Alan Coopersmith
-
2024/09/06
[oss-security] CVE-2024-7012, CVE-2024-7923: Authentication bypass in Foreman & Pulpcore
Christian Hoffmann
-
2024/09/06
[oss-security] CVE-2024-45034: Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes
Ephraim Anierobi
-
2024/09/06
[oss-security] CVE-2024-45498: Apache Airflow: Command Injection in an example DAG
Ephraim Anierobi
-
2024/09/06
Re: [oss-security] Linux kernel: memory leak in arch/powerpc/platforms/powernv/opal-irqchip.c: opal_event_init()
Michael Ellerman
-
2024/09/05
[oss-security] Go 1.23.1 and Go 1.22.7 released with 3 security fixes
Alan Coopersmith
-
2024/09/04
[oss-security] [OSSA-2024-003] OpenStack Ironic: Unvalidated image data passed to qemu-img (CVE-2024-44082)
Brian Rosmaita
-
2024/09/04
[oss-security] CVE-2024-43402: Rust before 1.81.0 didn't fully fix argument escaping for batch files
Pietro Albini
-
2024/09/04
[oss-security] Re: CVE-2024-45310: runc can be tricked into creating empty files/directories on host
Aleksa Sarai
-
2024/09/04
[oss-security] Webmin UDP/10000 discovery service Loop DoS (COK-2024-05-05)
Sergei G
-
2024/09/03
[oss-security] CVE-2024-45507: Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE
Jacques Le Roux
-
2024/09/03
[oss-security] CVE-2024-45195: Apache OFBiz: Confused controller-view authorization logic (forced browsing)
Jacques Le Roux
-
2024/09/03
[oss-security] CPython: [CVE-2024-6232] Regular-expression DoS when parsing TarFile headers
Alan Coopersmith
-
2024/09/03
[oss-security] CVE-2024-6119: OpenSSL: Possible denial of service in X.509 name checks
Tomas Mraz
-
2024/09/03
[oss-security] Django CVE-2024-45230 and CVE-2024-45231
Natalia Bidart
-
2024/09/03
Re: [oss-security] CVE-2024-45310: runc can be tricked into creating empty files/directories on host
Mike O'Connor
-
2024/09/02
[oss-security] CVE-2024-45310: runc can be tricked into creating empty files/directories on host
Aleksa Sarai
-
2024/09/02
Re: [oss-security] Linux kernel: memory leak in arch/powerpc/platforms/powernv/opal-irqchip.c: opal_event_init()
Solar Designer
-
2024/09/02
[oss-security] Linux kernel: memory leak in arch/powerpc/platforms/powernv/opal-irqchip.c: opal_event_init()
2639161967
-
2024/08/31
[oss-security] [vim-security] heap-buffer-overflow in Vim > 9.1.0038 && < 9.1.0707
Christian Brabandt
-
2024/08/26
[oss-security] CVE-2023-49582: Apache Portable Runtime (APR): Unexpected lax shared memory permissions
Eric Covener
-
2024/08/25
[oss-security] [vim-security] heap-buffer-overflow in ins_typebuf() in Vim < 9.1.0697
Christian Brabandt
-
2024/08/23
Re: [oss-security] CPython: CVE-2024-8088: Infinite loop when iterating over zip archive entry names
Fay Stegerman
-
2024/08/23
Re: [oss-security] CPython: CVE-2024-8088: Infinite loop when iterating over zip archive entry names
Fay Stegerman
-
2024/08/22
Re: [oss-security] CPython: CVE-2024-8088: Infinite loop when iterating over zip archive entry names
Fay Stegerman
-
2024/08/22
[oss-security] [vim-security] heap-buffer-overflow in do_search() in Vim < 9.1.0689
Christian Brabandt
-
2024/08/22
[oss-security] gh:facebook/rocksdb v9.5.2 - SupplyChainAttackPoC for Meta BB
Andreas Stieger
-
2024/08/22
[oss-security] CPython: CVE-2024-8088: Infinite loop when iterating over zip archive entry names
Alan Coopersmith
-
2024/08/21
[oss-security] CVE-2024-41937: Apache Airflow: Stored XSS Vulnerability on provider link
Ephraim Anierobi
-
2024/08/21
[oss-security] CVE-2023-49198: Apache SeaTunnel Web: Arbitrary file read vulnerability
Jun Gao
-
2024/08/20
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jacob Bachmeyer
-
2024/08/20
[oss-security] CVE-2024-22281: Apache Helix Front (UI): Helix front hard-coded secret in the express-session
Junkai Xue
-
2024/08/20
[oss-security] CVE-2024-43202: Apache DolphinScheduler: Remote Code Execution Vulnerability
ShunFeng Cai
-
2024/08/20
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Steffen Nurpmeso
-
2024/08/19
Re: [oss-security] AI Cyber Challenge (AIxCC) semi-final results from DEF CON 32 (2024)
David A. Wheeler
-
2024/08/19
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jacob Bachmeyer
-
2024/08/18
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Peter Gutmann
-
2024/08/17
Re: [oss-security] AI Cyber Challenge (AIxCC) semi-final results from DEF CON 32 (2024)
Alfredo Ortega
-
2024/08/17
[oss-security] Landlock Houdini fix: CVE-2024-42318
Mickaël Salaün
-
2024/08/17
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jacob Bachmeyer
-
2024/08/16
[oss-security] WebKitGTK and WPE WebKit Security Advisory WSA-2024-0004
Adrian Perez de Castro
-
2024/08/16
[oss-security] AI Cyber Challenge (AIxCC) semi-final results from DEF CON 32 (2024)
David A. Wheeler
-
2024/08/16
[oss-security] Unbound 1.21.0 released with multiple security fixes
Alan Coopersmith
-
2024/08/16
[oss-security] [kubernetes] CVE-2024-7646: Ingress-nginx Annotation Validation Bypass
Craig Ingram
-
2024/08/16
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jeffrey Walton
-
2024/08/16
[oss-security] Heads-up: there are two versions of Intel microcode update IPU 2024.3
Samuel Verschelde
-
2024/08/16
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jacob Bachmeyer
-
2024/08/16
Re: [oss-security] collision confounders (was: feedback requested regarding deprecation of TLS 1.0/1.1)
Jacob Bachmeyer
-
2024/08/15
[oss-security] [vim-security] use-after-free in alist_add() in Vim < v9.1.0678
Christian Brabandt
-
2024/08/15
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Peter Gutmann
-
2024/08/15
[oss-security] Dovecot CVE-2024-23185: Very large headers can cause resource exhaustion when parsing message
Aki Tuomi
-
2024/08/15
[oss-security] Dovecot CVE-2024-23184: Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive
Aki Tuomi
-
2024/08/15
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jacob Bachmeyer
-
2024/08/15
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Hanno Böck
-
2024/08/14
Re: [oss-security] Tracking down a lost CVE request (MITRE)
Michael Orlitzky
-
2024/08/14
Re: [oss-security] Tracking down a lost CVE request (MITRE)
Mark Esler
-
2024/08/14
[oss-security] flatpak CVE-2024-42472: Access to files outside sandbox for apps using persistent= (--persist)
Simon McVittie
-
2024/08/14
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Pat Gunn
-
2024/08/14
[oss-security] CVE-2024-7347: nginx: ngx_http_mp4_module: Worker process crash by using a specially crafted mp4 file
Solar Designer
-
2024/08/14
[oss-security] Xen Security Advisory 461 v2 (CVE-2024-31146) - PCI device pass-through with shared resources
Xen . org security team
-
2024/08/14
[oss-security] Xen Security Advisory 460 v2 (CVE-2024-31145) - error handling in x86 IOMMU identity mapping
Xen . org security team
-
2024/08/14
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Mike O'Connor
-
2024/08/12
[oss-security] CVE-2024-41909: Apache MINA SSHD: integrity check bypass
Arnout Engelen
-
2024/08/12
[oss-security] CVE-2024-42008 and more: XSS vulnerabilities in Roundcube webmail
Valtteri Vuorikoski
-
2024/08/11
[oss-security] CVE-2024-7348: PostgreSQL relation replacement during pg_dump executes arbitrary SQL
Solar Designer
-
2024/08/09
[oss-security] CVE-2024-30188: Apache DolphinScheduler: Resource File Read And Write Vulnerability
ShunFeng Cai
-
2024/08/09
[oss-security] CVE-2024-29831: Apache DolphinScheduler: RCE by arbitrary js execution
ShunFeng Cai
-
2024/08/09
[oss-security] CVE-2024-41888: Apache Answer: The link for resetting user password is not Single-Use
Enxin Xie
-
2024/08/09
[oss-security] CVE-2024-41890: Apache Answer: The link to reset the user's password will remain valid after sending a new link
Enxin Xie
-
2024/08/09
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jens Timmerman
-
2024/08/09
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Peter Gutmann
-
2024/08/09
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jacob Bachmeyer
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
steffen
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Steffen Nurpmeso
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Steffen Nurpmeso
-
2024/08/08
[oss-security] KL-001-2024-006: Open WebUI Arbitrary File Upload + Path Traversal
KoreLogic Disclosures
-
2024/08/08
[oss-security] KL-001-2024-005: Open WebUI Stored Cross-Site Scripting
KoreLogic Disclosures
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Clemens Lang
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Clemens Lang
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Duncan Grisby
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Demi Marie Obenour
-
2024/08/08
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jeffrey Walton
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Steffen Nurpmeso
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Marco Moock
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Pat Gunn
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Solar Designer
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Demi Marie Obenour
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
niekt0
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Dan Kegel
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Steffen Nurpmeso
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jeffrey Walton
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Chad Sheridan
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Neil Horman
-
2024/08/07
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Bob Friesenhahn
-
2024/08/07
[oss-security] Multiple vulnerabilities in Jenkins
Daniel Beck
-
2024/08/06
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Jan Engelhardt
-
2024/08/06
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Alex Gaynor
-
2024/08/06
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Demi Marie Obenour
-
2024/08/06
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Marco Moock
-
2024/08/06
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Demi Marie Obenour
-
2024/08/06
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Clemens Lang
-
2024/08/06
Re: [oss-security] feedback requested regarding deprecation of TLS 1.0/1.1
Neil Horman