oss-security mailing list
Recent messages:
- 2025/08/10 #4:
[vim-security] A double-free was found in Vim >v9.1.1231 and <
9.1.1406 (Christian Brabandt <cb@...bit.org>)
- 2025/08/10 #3:
[vim-security] heap use-after-free was found in Vim < 9.1.1400 (Christian Brabandt <cb@...bit.org>)
- 2025/08/10 #2:
Re: CVE-2025-55188: 7-Zip: Arbitrary file write on
extraction, may lead to code execution (lunbun <lunbun021@...il.com>)
- 2025/08/10 #1:
Re: CVE-2025-55188: 7-Zip: Arbitrary file write on
extraction, may lead to code execution (Jacob Bachmeyer <jcb62281@...il.com>)
- 2025/08/09 #1:
CVE-2025-55188: 7-Zip: Arbitrary file write on extraction, may lead
to code execution (lunbun <lunbun021@...il.com>)
- 2025/08/08 #2:
Re: StarDict sends the user's X11 selection to the network (Maytham Alsudany <maytham@...ian.org>)
- 2025/08/08 #1:
Re: Five new CVEs published for Cyberark Conjur OSS (Solar Designer <solar@...nwall.com>)
- 2025/08/07 #2:
CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE (Colm O hEigeartaigh <coheigea@...che.org>)
- 2025/08/07 #1:
CVE-2025-53606: Apache Seata (incubating): Deserialization of
untrusted Data in Apache Seata Server (Min Ji <jimin@...che.org>)
- 2025/08/06 #1:
CVE-2025-47906 & CVE-2025-47907 fixed in Go 1.24.6 &
1.23.12 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/08/05 #1:
CVE-2025-54466: Apache OFBiz: RCE Vulnerability in scrum plugin (Nicolas Malin <nmalin@...che.org>)
- 2025/08/04 #1:
StarDict sends the user's X11 selection to the network (Vincent Lefevre <vincent@...c17.net>)
- 2025/08/03 #5:
CVE-2024-51775: Apache Zeppelin: Command Injection via CSWSH (PJ Fanning <fanningpj@...che.org>)
- 2025/08/03 #4:
CVE-2024-41177: Apache Zeppelin: XSS in the Helium module (PJ Fanning <fanningpj@...che.org>)
- 2025/08/03 #3:
CVE-2024-52279: Apache Zeppelin: Arbitrary file read by adding
malicious JDBC connection string (PJ Fanning <fanningpj@...che.org>)
- 2025/08/03 #2:
Re: Linux kernel: eBPF vulnerabilities (Demi Marie Obenour <demiobenour@...il.com>)
- 2025/08/03 #1:
Linux kernel: eBPF vulnerabilities (Solar Designer <solar@...nwall.com>)
- 2025/08/02 #1:
WebKitGTK and WPE WebKit Security Advisory WSA-2025-0005 (Adrian Perez de Castro <aperez@...lia.com>)
- 2025/07/31 #1:
Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper
configuration (CVSS v4.0 Score: 9.3 / Critical) ("Sandro Gauci" <sandro@...blesecurity.com>)
- 2025/07/30 #3:
CVE-2025-24854: Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki
Image plugin (Juan Pablo Santos Rodríguez <juanpablo@...che.org>)
- 2025/07/30 #2:
CVE-2025-24853: Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki
Header Link processing (Juan Pablo Santos Rodríguez <juanpablo@...che.org>)
- 2025/07/30 #1:
CVE-2025-54656: Apache Struts Extras: Improper Output
Neutralization for Logs (Arnout Engelen <engelen@...che.org>)
- 2025/07/29 #1:
Re: Fwd:[CVE-2025-8194] Cpython Tarfile
infinite loop during parsing with negative member offset (Seth Larson <seth@...hon.org>)
- 2025/07/28 #2:
Re: Fwd:[CVE-2025-8194] Cpython Tarfile infinite loop
during parsing with negative member offset (Mats Wichmann <mats@...hmann.us>)
- 2025/07/28 #1:
Fwd:[CVE-2025-8194] Cpython Tarfile infinite loop
during parsing with negative member offset (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/07/24 #2:
CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always
evaluates to true in 2.4.64 (Eric Covener <covener@...che.org>)
- 2025/07/24 #1:
Re: CVE-2025-30761:A vulnerability in JDK's Nashorn Allows for Arbitrary Code Execution ("liyajie" <liyajie@...neuler.sh>)
- 2025/07/23 #1:
The GNU C Library security advisories update for 2025-07-23 (Adhemerval Zanella Netto <adhemerval.zanella@...aro.org>)
- 2025/07/22 #3:
non-issues in dailyaidecheck script in Debian's packaging of AIDE (Solar Designer <solar@...nwall.com>)
- 2025/07/22 #2:
Re: Fwd: Node.js security updates for all active release lines, July 2025 (Solar Designer <solar@...nwall.com>)
- 2025/07/22 #1:
[kubernetes] CVE-2025-7342: VM images built with Kubernetes Image
Builder Nutanix or OVA providers use default credentials … (Rita Zhang <rita.z.zhang@...il.com>)
- 2025/07/21 #3:
Re: CVE-2025-30761:A vulnerability in JDK's Nashorn Allows for Arbitrary Code Execution (Moritz Bechler <mbechler@...terphace.org>)
- 2025/07/21 #2:
CVE-2025-50151: Apache Jena: Configuration files uploaded by
administrative users are not check properly (Andy Seaborne <andy@...che.org>)
- 2025/07/21 #1:
CVE-2025-49656: Apache Jena: Administrative users can create files
outside the server directory space via the admin UI (Andy Seaborne <andy@...che.org>)
- 2025/07/18 #3:
Re: CVE-2025-53367: An exploitable OOB write in DjVuLibre (Kevin Backhouse <kevinbackhouse@...hub.com>)
- 2025/07/18 #2:
CVE-2025-53817: Null pointer dereference in 7-Zip before 25.00 (Jaras <jarlob@...il.com>)
- 2025/07/18 #1:
CVE-2025-53816: Memory corruption in 7-Zip before 25.00 (Jaras <jarlob@...il.com>)
- 2025/07/16 #7:
Five new CVEs published for Cyberark Conjur OSS (Andy Tinkham <andy.tinkham@...erark.com>)
- 2025/07/16 #6:
ISC has disclosed one vulnerability in BIND 9 (CVE-2025-40777) ("Everett B. Fulton" <ebf@....org>)
- 2025/07/16 #5:
CVE-2025-40918: Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through
2.1800 for Perl generates the cnonce insecurely (Robert Rothenberg <rrwo@...n.org>)
- 2025/07/16 #4:
CVE-2025-40923: Plack-Middleware-Session before version 0.35 for Perl
generates session ids insecurely (Robert Rothenberg <rrwo@...n.org>)
- 2025/07/16 #3:
CVE-2025-23267:A vulnerability in NVIDIA Container Toolkit can lead to container escape. ("liyajie" <liyajie@...neuler.sh>)
- 2025/07/16 #2:
Fwd: Node.js security updates for all active release lines, July
2025 (Rafael Gonzaga <work@...aelgss.dev>)
- 2025/07/16 #1:
CVE-2025-30761:A vulnerability in JDK's Nashorn Allows for Arbitrary Code Execution ("liyajie" <liyajie@...neuler.sh>)
- 2025/07/15 #3:
CVE-2025-48795: Apache CXF: Denial of Service and sensitive data
exposure in logs (Colm O hEigeartaigh <coheigea@...che.org>)
- 2025/07/15 #2:
[vim-security]: path traversal issue with zip.vim and special
crafted zip archives in Vim < v9.1.1551 (Christian Brabandt <cb@...bit.org>)
- 2025/07/15 #1:
[vim-security] path traversal issue with tar.vim and special crafted
tar archives in Vim < 9.1.1552 (Christian Brabandt <cb@...bit.org>)
- 2025/07/14 #1:
CVE-2025-53689: Apache Jackrabbit: XXE vulnerability in
jackrabbit-spi-commons (Julian Reschke <reschke@...che.org>)
- 2025/07/13 #1:
https://issues.apache.org/jira/browse/ZEPPELIN-6101:
CVE-2024-41169: Apache Zeppelin: raft directory listing and file read (PJ Fanning <fanningpj@...che.org>)
- 2025/07/12 #1:
Re: GHSL-2025-054: Use After Free (UAF) in Poppler - CVE-2025-52886 (Kevin Backhouse <kevinbackhouse@...hub.com>)
- 2025/07/11 #5:
GHSL-2025-054: Use After Free (UAF) in Poppler -
CVE-2025-52886 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/07/11 #4:
PHP security releases 8.4.10, 8.3.23, 8.2.29, 8.1.33 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/07/11 #3:
gnutls 3.8.10 fixes 4 CVEs (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/07/11 #2:
Re: 5 security issues disclosed in libxml2 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/07/11 #1:
CVE-2025-48924: Apache Commons Lang:
ClassUtils.getClass(...) can throw a StackOverflowError on very long
inputs ("Gary D. Gregory" <ggregory@...che.org>)
- 2025/07/10 #13:
CVE-2025-53506: Apache Tomcat: DoS via excessive h2 streams at
connection start (Mark Thomas <markt@...che.org>)
- 2025/07/10 #12:
CVE-2025-52520: Apache Tomcat: DoS via integer overflow in multipart
file upload (Mark Thomas <markt@...che.org>)
- 2025/07/10 #11:
CVE-2025-52434: Apache Tomcat: APR/Native Connector crash leading to
DoS (Mark Thomas <markt@...che.org>)
- 2025/07/10 #10:
CVE-2025-53020: Apache HTTP Server: HTTP/2 DoS by Memory Increase (Eric Covener <covener@...che.org>)
- 2025/07/10 #9:
CVE-2025-49812: Apache HTTP Server: mod_ssl TLS upgrade attack (Eric Covener <covener@...che.org>)
- 2025/07/10 #8:
CVE-2025-23048: Apache HTTP Server: mod_ssl access control bypass
with session resumption (Eric Covener <covener@...che.org>)
- 2025/07/10 #7:
CVE-2025-49630: Apache HTTP Server: mod_proxy_http2 denial of
service (Eric Covener <covener@...che.org>)
- 2025/07/10 #6:
CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable
escaping (Eric Covener <covener@...che.org>)
- 2025/07/10 #5:
CVE-2024-43394: Apache HTTP Server: SSRF on Windows due to UNC
paths (Eric Covener <covener@...che.org>)
- 2025/07/10 #4:
CVE-2024-43204: Apache HTTP Server: SSRF with mod_headers setting
Content-Type header (Eric Covener <covener@...che.org>)
- 2025/07/10 #3:
CVE-2024-42516: Apache HTTP Server: HTTP response splitting (Eric Covener <covener@...che.org>)
- 2025/07/10 #2:
CVE fixes in Apache HTTP Server 2.4.64 (Solar Designer <solar@...nwall.com>)
- 2025/07/10 #1:
Release of pqcscan ("Vincent Berg" <gvb@...ilax.io>)
- 2025/07/09 #4:
Multiple vulnerabilities in Jenkins plugins (Kevin Guerroudj <kguerroudj@...udbees.com>)
- 2025/07/09 #3:
Opossum attack / Opportunistic HTTP (RFC 2817) insecure (Hanno Böck <hanno@...eck.de>)
- 2025/07/09 #2:
Re: Fwd: Node.js security updates for all active
release lines, May 2025 (Salvatore Bonaccorso <carnil@...ian.org>)
- 2025/07/09 #1:
Re: Fwd: Node.js security updates for all active release lines, May 2025 (Solar Designer <solar@...nwall.com>)
- 2025/07/08 #5:
Go 1.24.5 & 1.23.11 fix CVE-2025-4674 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/07/08 #4:
Multiple vulnerabilities fixed in Git (Taylor Blau <me@...ylorr.com>)
- 2025/07/08 #3:
Fwd: Node.js security updates for all active release lines, May
2025 (Rafael Gonzaga <work@...aelgss.dev>)
- 2025/07/08 #2:
Xen Security Advisory 471 v1 (CVE-2024-36350,CVE-2024-36357) -
x86: Transitive Scheduler Attacks (Xen.org security team <security@....org>)
- 2025/07/08 #1:
Re: Electric Charger Research (Solar Designer <solar@...nwall.com>)
- 2025/07/07 #2:
Electric Charger Research (Brandon Perry <bperry.volatile@...il.com>)
- 2025/07/07 #1:
Re: CVE-2025-27446: Apache APISIX Java Plugin Runner: Local listening
file permissions in APISIX plugin runner allow a loc… (Cuong Duy <duycuong200798@...il.com>)
- 2025/07/06 #1:
CVE-2025-27446: Apache APISIX Java Plugin Runner: Local listening
file permissions in APISIX plugin runner allow a local a… (YuanSheng Wang <membphis@...che.org>)
- 2025/07/05 #1:
Re: DoS segfault (NULL pointer deref) in SOPE / SOGo (Salvatore Bonaccorso <carnil@...ian.org>)
- 2025/07/03 #1:
CVE-2025-53367: An exploitable OOB write in DjVuLibre (Kevin Backhouse <kevinbackhouse@...hub.com>)
- 2025/07/02 #3:
DoS segfault (NULL pointer deref) in SOPE / SOGo (Stefan Bühler <source@...uehler.de>)
- 2025/07/02 #2:
CVE-2025-38089: Linux kernel: NFS server remote DoS via NULL pointer dereference (tianshuo han <hantianshuo233@...il.com>)
- 2025/07/02 #1:
CVE-2025-46647: Apache APISIX: improper validation of issuer from
introspection discovery url in plugin openid-connect (Junxu Chen <chenjunxu@...che.org>)
- 2025/07/01 #2:
CVE-2024-35164: Apache Guacamole: Improper input validation of
console codes (Michael Jumper <mjumper@...che.org>)
- 2025/07/01 #1:
Xen Security Advisory 470 v2 (CVE-2025-27465) - x86: Incorrect
stubs exception handling for flags recovery (Xen.org security team <security@....org>)
- 2025/06/30 #3:
CVE-2025-32463: sudo local privilege escalation via chroot option ("Todd C. Miller" <Todd.Miller@...o.ws>)
- 2025/06/30 #2:
CVE-2025-32462: sudo local privilege escalation via host option ("Todd C. Miller" <Todd.Miller@...o.ws>)
- 2025/06/30 #1:
CVE-2024-39954: Apache EventMesh Runtime: SSRF (Xue Weiming <mikexue@...che.org>)
- 2025/06/28 #1:
CVE-2025-32897: Apache Seata (incubating): Deserialization of
untrusted Data in Apache Seata Server (Min Ji <jimin@...che.org>)
- 2025/06/27 #2:
libssh 0.11.2 security and bugfix release (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/06/27 #1:
Re: CVE-2025-52555 Ceph: CephFS Permission Escalation
Vulnerability in Ceph Fuse mounted FS (Jacob Bachmeyer <jcb62281@...il.com>)
- 2025/06/26 #1:
CVE-2025-52555 Ceph: CephFS Permission Escalation Vulnerability in
Ceph Fuse mounted FS ("Sage [They / Them] McTaggart" <amctagga@...hat.com>)
- 2025/06/25 #1:
Re: sox_ng fixes 20 CVEs in sox (Martin Guy <martinwguy@...il.com>)
- 2025/06/24 #8:
Re: xdg-open bypassing SameSite=Strict (Lucas Holt <luke@...lishgames.com>)
- 2025/06/24 #7:
Re: xdg-open bypassing SameSite=Strict (Gabriel Corona <gabriel.corona@...e.fr>)
- 2025/06/24 #6:
Re: xdg-open bypassing SameSite=Strict (Anton Luka Šijanec <anton@...anec.eu>)
- 2025/06/24 #5:
Re: xdg-open bypassing SameSite=Strict (grape mingijung <mingijung.grape@...il.com>)
- 2025/06/24 #4:
sox_ng fixes 20 CVEs in sox (Martin Guy <martinwguy@...il.com>)
31345 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.