oss-security mailing list
Recent messages:
- 2025/12/02 #1:
expat looking for help with another unfixed non-public
denial-of-service vulnerability [CVE-2025-66382] (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/01 #6:
Re: 5 CVE's fixed in Fluent Bit (Christian Brabandt <cb@...bit.org>)
- 2025/12/01 #5:
CVE-2025-12183 in lz4-java, fixed in new fork (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/01 #4:
[kubernetes] CVE-2025-13281: Portworx Half-Blind SSRF in kube-controller-manager (Nathan Herz <nathan.herz97@...il.com>)
- 2025/12/01 #3:
WebKitGTK and WPE WebKit Security Advisory WSA-2025-0008 (Adrian Perez de Castro <aperez@...lia.com>)
- 2025/12/01 #2:
CVE-2025-64775: Apache Struts: File leak in multipart request
processing causes disk exhaustion (DoS) - S2-068 (Lukasz Lenart <lukaszlenart@...che.org>)
- 2025/12/01 #1:
CVE-2025-59789: Apache bRPC: Stack Exhaustion via Unbounded
Recursion in JSON Parser (Wang Weibing <wwbmmm@...che.org>)
- 2025/11/28 #3:
CVE-2025-59792: Apache Kvrocks: MONITOR command reveals plaintext
credentials to non-admins (Hulk Lin <hulk@...che.org>)
- 2025/11/28 #2:
CVE-2025-59790: Apache Kvrocks: RESET command grants admin
privileges (Hulk Lin <hulk@...che.org>)
- 2025/11/28 #1:
CVE-2023-48796: Apache DolphinScheduler: Sensitive information
disclosure (Lidong Dai <lidongdai@...che.org>)
- 2025/11/27 #5:
CVE-2025-61915 cups: Local denial-of-service via cupsd.conf update
and related issues (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/27 #4:
CVE-2025-58436 cups: Slow client communication leads to a possible
DoS attack (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/27 #3:
CVE-2025-59454: Apache CloudStack: Lack of user permission
validation leading to data leak for few APIs (Harikrishna Patnala <harikrishna@...che.org>)
- 2025/11/27 #2:
CVE-2025-59302: Apache CloudStack: Potential remote code execution
on Javascript engine defined rules (Harikrishna Patnala <harikrishna@...che.org>)
- 2025/11/27 #1:
CVE-2025-54057: Apache SkyWalking: Stored XSS vulnerability (Zhenxu Ke <kezhenxu94@...che.org>)
- 2025/11/26 #4:
Unbound: 1.24.2 addresses CVE-2025-11411 (again) (Yorgos Thessalonikefs <yorgos@...etlabs.nl>)
- 2025/11/26 #3:
CVE-2025-62728: Apache Hive: SQL injection vulnerability when
processing delete column statistics requests via the HMS … (Stamatis Zampetakis <zabetak@...che.org…)
- 2025/11/26 #2:
5 CVE's fixed in Fluent Bit (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/26 #1:
CVE-2025-59390: Apache Druid: Kerberos authenticaton chooses a
cryptographically unsecure secret if not configured explicitly. (Karan Kumar <karan@...che.org>)
- 2025/11/24 #1:
CVE-2025-65998: Apache Syncope: Default AES key used for internal
password encryption (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2025/11/22 #1:
libpng 1.6.51: Four buffer overflow vulnerabilities fixed:
CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, CVE-2025-65018 (Cosmin Truta <ctruta@...il.com>)
- 2025/11/20 #2:
gnutls 3.8.11 released with fix for CVE-2025-9820 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/20 #1:
CVE-2025-64524 cups-filters: Heap Buffer Overflow in rastertopclx
Filter Leading to Potential Arbitrary Code Execution (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/19 #1:
CVE-2025-64408: Apache Causeway: Java deserialization vulnerability
to authenticated attackers (Dan Haywood <danhaywood@...che.org>)
- 2025/11/18 #10:
Re: SQLite - Integer Overflow in FTS5 Extension
[CVE-2025-7709] ("John Hein" <josec-ml0@...mail.com>)
- 2025/11/18 #9:
[SECURITY PATCH 8/8] commands/usbtest: Ensure string length is sufficient in usb string processing (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #8:
[SECURITY PATCH 7/8] commands/usbtest: Use correct string length field (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #7:
[SECURITY PATCH 6/8] tests/lib/functional_test: Unregister commands on module unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #6:
[SECURITY PATCH 5/8] normal/main: Unregister commands on module unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #5:
[SECURITY PATCH 4/8] gettext/gettext: Unregister gettext command on module unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #4:
[SECURITY PATCH 3/8] net/net: Unregister net_set_vlan command on unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #3:
[SECURITY PATCH 2/8] kern/file: Call grub_dl_unref() after fs->fs_close() (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #2:
[SECURITY PATCH 1/8] commands/test: Fix error in recursion depth calculation (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #1:
[SECURITY PATCH 0/8] GRUB2 vulnerabilities - 2025/11/18 (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/17 #6:
[OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3
token endpoints can grant Keystone authorization (CVE-2… (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/17 #5:
Re: [OSSA-2025-002] OpenStack Keystone:
Unauthenticated access to EC2/S3 token endpoints can grant Keystone
authorization (… (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/17 #4:
lightdm-kde-greeter: Privilege Escalation from lightdm Service User
to root in KAuth Helper Service (CVE-2025-62876) (Matthias Gerstner <mgerstner@...e.de>)
- 2025/11/17 #3:
Re: CVE-2025-40300 / VMScape (Solar Designer <solar@...nwall.com>)
- 2025/11/17 #2:
Re: CVE-2025-40300 / VMScape (Bjoern Franke <bjo@...afweide.org>)
- 2025/11/17 #1:
GitGuardian GGShield SSL/TLS Verification Bypass (No CVE) (tanish saxena <tanish.saxena26@...il.com>)
- 2025/11/16 #1:
Re: [OSSA-2025-002] OpenStack Keystone:
Unauthenticated access to EC2/S3 token endpoints can grant Keystone
authorizat… (Salvatore Bonaccorso <carnil@...ian.org…)
- 2025/11/15 #1:
Re: Questionable CVE's reported against dnsmasq (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/14 #7:
PostgreSQL releases fixes for CVE-2025-12817 &
CVE-2025-12818 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/14 #6:
Re: CVE-2025-40300 / VMScape (Moritz Mühlenhoff <jmm@...til.org>)
- 2025/11/14 #5:
Re: Questionable CVE's reported against dnsmasq (Jeffrey Walton <noloader@...il.com>)
- 2025/11/14 #4:
Re: CVE-2025-40300 / VMScape (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/14 #3:
CVE-2025-40300 / VMScape (Bjoern Franke <bjo@...afweide.org>)
- 2025/11/14 #2:
Re: Questionable CVE's reported against dnsmasq (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/14 #1:
Re: Questionable CVE's reported against dnsmasq (Jacob Bachmeyer <jcb62281@...il.com>)
- 2025/11/13 #2:
Re: Questionable CVE's reported against dnsmasq (Alexander Patrakov <patrakov@...il.com>)
- 2025/11/13 #1:
Re: Questionable CVE's reported against dnsmasq (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/12 #2:
CVE-2025-64503 libcupsfilters, cups-filters 1.x: out of bounds write
in pdftoraster (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/12 #1:
CVE-2025-57812 libcupsfilters, cups-filters 1.x: Multiple
TIFF-related issues in libcupsfilters (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/11 #10:
CVE-2025-64407: Apache OpenOffice: URL fetching can be used to
exfiltrate arbitrary INI file values and environment variab… (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #9:
CVE-2025-64406: Apache OpenOffice: Possible memory corruption
during CSV import (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #8:
CVE-2025-64405: Apache OpenOffice: Remote documents loaded without
prompt via DDE function (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #7:
CVE-2025-64404: Apache OpenOffice: Remote documents loaded without
prompt via background and bullet images (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #6:
CVE-2025-64403: Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #5:
CVE-2025-64402: Apache OpenOffice: Remote documents loaded without
prompt via OLE objects (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #4:
CVE-2025-64401: Apache OpenOffice: Remote documents loaded without
prompt via IFrame (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #3:
CVE-2024-47866 Ceph: RGW DoS via improper input validation. ("Sage [They / Them] McTaggart" <amctagga@...hat.com>)
- 2025/11/11 #2:
CVE-2025-61623: Apache OFBiz: Reflected Cross-site Scripting (Jacques Le Roux <jleroux@...che.org>)
- 2025/11/11 #1:
CVE-2025-59118: Apache OFBiz: Critical Remote Command Execution
via Unrestricted File Upload (Jacques Le Roux <jleroux@...che.org>)
- 2025/11/07 #2:
Re: runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 (Ali Polatel <alip@...sys.org>)
- 2025/11/07 #1:
Re: Becoming a CVE Naming Authority for your project (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/06 #6:
Re: Becoming a CVE Naming Authority for your project (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/06 #5:
Re: Becoming a CVE Naming Authority for your project (Pat Gunn <pgunn01@...il.com>)
- 2025/11/06 #4:
Re: Becoming a CVE Naming Authority for your project ("Olle E. Johansson" <oej@...ina.net>)
- 2025/11/06 #3:
Re: Questionable CVE's reported against dnsmasq ("Olle E. Johansson" <oej@...ina.net>)
- 2025/11/06 #2:
Re: runc container breakouts via procfs writes:
CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 ("akendo@...ndo.eu" <akendo@...ndo.eu>)
- 2025/11/06 #1:
scx: Unauthenticated scx_loader D-Bus Service can lead to major
Denial-of-Service (Matthias Gerstner <mgerstner@...e.de>)
- 2025/11/05 #18:
Re: Questionable CVE's reported against dnsmasq (Pedro Sampaio <psampaio@...hat.com>)
- 2025/11/05 #17:
Re: Becoming a CVE Naming Authority for your project (Pedro Sampaio <psampaio@...hat.com>)
- 2025/11/05 #16:
Re: Becoming a CVE Naming Authority for your project (Pedro Sampaio <psampaio@...hat.com>)
- 2025/11/05 #15:
Re: Becoming a CVE Naming Authority for your project (Art Manion <zmanion@...tonmail.com>)
- 2025/11/05 #14:
Re: Becoming a CVE Naming Authority for your project (Matthew Fernandez <matthew.fernandez@...il.com>)
- 2025/11/05 #13:
Re: [OSSA-2025-002] OpenStack Keystone:
Unauthenticated access to EC2/S3 token endpoints can grant Keystone
authorization (… (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/05 #12:
Django CVE-2025-64458 and CVE-2025-64459 (Natalia Bidart <nataliabidart@...ngoproject.com>)
- 2025/11/05 #11:
Re: Becoming a CVE Naming Authority for your project (Yogesh Mittal <ymittal@...hat.com>)
- 2025/11/05 #10:
Re: Becoming a CVE Naming Authority for your project (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/05 #9:
Re: Questionable CVE's reported against dnsmasq ("Olle E. Johansson" <oej@...ina.net>)
- 2025/11/05 #8:
Re: Becoming a CVE Naming Authority for your project ("Olle E. Johansson" <oej@...ina.net>)
- 2025/11/05 #7:
Re: [CVE-2019-18860] SQUID-2023:6 Cross Site Scripting
in cachemgr.cgi (Amos Jeffries <squid3@...enet.co.nz>)
- 2025/11/05 #6:
[CVE-2025-62168] SQUID-2025:2 Information Disclosure in Error
handling (Amos Jeffries <squid3@...enet.co.nz>)
- 2025/11/05 #5:
[CVE-2025-54574] SQUID-2025:1 Buffer Overflow in URN Handling (Amos Jeffries <squid3@...enet.co.nz>)
- 2025/11/05 #4:
Xen Security Advisory 471 v3 (CVE-2024-36350,CVE-2024-36357) -
x86: Transitive Scheduler Attacks (Xen.org security team <security@....org>)
- 2025/11/05 #3:
runc container breakouts via procfs writes: CVE-2025-31133,
CVE-2025-52565, and CVE-2025-52881 (Aleksa Sarai <cyphar@...har.com>)
- 2025/11/05 #2:
[SECURITY ADVISORY] curl: missing SFTP host verification with
wolfSSH (Daniel Stenberg <daniel@...x.se>)
- 2025/11/05 #1:
Re: [CVE-2019-18860] SQUID-2023:6 Cross Site Scripting in cachemgr.cgi (Solar Designer <solar@...nwall.com>)
- 2025/11/04 #9:
Re: Becoming a CVE Naming Authority for your project (Greg KH <greg@...ah.com>)
- 2025/11/04 #8:
Re: [OSSA-2025-002] OpenStack Keystone:
Unauthenticated access to EC2/S3 token endpoints can grant Keystone
authorizat… (Demi Marie Obenour <demiobenour@...il.c…)
- 2025/11/04 #7:
[CVE-2019-18860] SQUID-2023:6 Cross Site Scripting in cachemgr.cgi (Amos Jeffries <squid3@...enet.co.nz>)
- 2025/11/04 #6:
Re: Questionable CVE's reported against dnsmasq (Art Manion <zmanion@...tonmail.com>)
- 2025/11/04 #5:
CVE-2025-58337: Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode for doris-mcp-serve… (Mingyu Chen <morningman@...che.org>)
- 2025/11/04 #4:
Becoming a CVE Naming Authority for your project (Rodrigo Freire <rfreire@...hat.com>)
- 2025/11/04 #3:
Re: Questionable CVE's reported against dnsmasq ("Olle E. Johansson" <oej@...ina.net>)
- 2025/11/04 #2:
[OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3
token endpoints can grant Keystone authorization (CVE P… (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/04 #1:
[SECURITY ADVISORY] wcurl path traversal with percent-encoded
slashes (Daniel Stenberg <daniel@...x.se>)
- 2025/11/03 #4:
Re: Questionable CVE's reported against dnsmasq (Demi Marie Obenour <demiobenour@...il.com>)
- 2025/11/03 #3:
Re: Questionable CVE's reported against dnsmasq (Art Manion <zmanion@...tonmail.com>)
31734 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.