Ubuntu Security Notice 4739-1 - A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
a5feb8fa066d0c3a1865f6e0f2147384
Ubuntu Security Notice 4738-1 - Paul Kehrer discovered that OpenSSL incorrectly handled certain input lengths in EVP functions. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer fields. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. Various other issues were also addressed.
ddd35a00ee36d9b3807f0f94e460031e
Backdoor.Win32.Agent.aak malware suffers from a buffer overflow vulnerability.
9c05bcd738259e6d2607b5bf2a011023
Batflat CMS versions 1.3.6 and below suffer from a remote code execution vulnerability.
f52fce6186b9cd8e4501a1b28755bac1
Ubuntu Security Notice 4737-1 - It was discovered that Bind incorrectly handled GSSAPI security policy negotiation. A remote attacker could use this issue to cause Bind to crash, resulting in a denial of service, or possibly execute arbitrary code. In the default installation, attackers would be isolated by the Bind AppArmor profile.
495d4f5b0aec882a3b44b696b0874475
Apport version 2.20 suffers from a local privilege escalation vulnerability.
41ed08c45f621a8c566d4fe5ff7b8474
Red Hat Security Advisory 2021-0423-01 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.6.17. Issues addressed include cross site scripting, denial of service, deserialization, and traversal vulnerabilities.
3fca77b118226960e302f343a05c7bfa
Backdoor.Win32.Agent.aak malware suffers from code execution and cross site request forgery vulnerabilities.
3709fd6065b0c25e41efd07763d6e07d
Backdoor.Win32.Agent.aak malware suffers from a hardcoded credential vulnerability.
59f7c8d08a2e0c4cbf04ec25fb6b102e
Gitea version 1.12.5 suffers from a remote code execution vulnerability.
043b07c09c159696122bfc666130307d