oss-security mailing list
Recent messages:
- 2025/12/09 #1:
CVE-2025-26866: Apache HugeGraph-Server: RAFT and deserialization vulnerability (VGalaxies <vgalaxies@...che.org>)
- 2025/12/08 #3:
Re: CVE-2025-62408: c-ares 1.32.3-1.34.5 use after
free() (Demi Marie Obenour <demiobenour@...il.com>)
- 2025/12/08 #2:
CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (Brad House <brad@...d-house.com>)
- 2025/12/08 #1:
PowerDNS Security Announcement 2025-07 and 2025-08 regarding
PowerDNS Recursor (Otto Moerbeek <otto.moerbeek@...erdns.com>)
- 2025/12/05 #5:
CPython vulnerable to CVE-2025-13836, CVE-2025-13837,
& CVE-2025-12084 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/05 #4:
CVE-2025-66418 & CVE-2025-66471 fixed in urllib3 2.6.0 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/05 #3:
Go 1.25.5 and Go 1.24.11 are released - fix
CVE-2025-61729 & CVE-2025-61727 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/05 #2:
CVE-2025-66566 fixed in lz4-java 1.10.1 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/05 #1:
Island: Sandboxing tool powered by Landlock (Mickaël Salaün <mic@...ikod.net>)
- 2025/12/04 #10:
React2Shell (CVE-2025-55182/CVE-2025-66478) (Jeffrey Walton <noloader@...il.com>)
- 2025/12/04 #9:
Re: [webkit-gtk] WebKitGTK and WPE WebKit Security Advisory
WSA-2025-0009 (Adrian Perez de Castro <aperez@...lia.com>)
- 2025/12/04 #8:
CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via
AllowOverride FileInfo (Eric Covener <covener@...che.org>)
- 2025/12/04 #7:
CVE-2025-65082: Apache HTTP Server: CGI environment variable
override (Eric Covener <covener@...che.org>)
- 2025/12/04 #6:
CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows
through UNC SSRF (Eric Covener <covener@...che.org>)
- 2025/12/04 #5:
CVE-2025-58098: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=... (Eric Covener <covener@...che.org>)
- 2025/12/04 #4:
CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended
retry intervals (Eric Covener <covener@...che.org>)
- 2025/12/04 #3:
WebKitGTK and WPE WebKit Security Advisory WSA-2025-0009 (Adrian Perez de Castro <aperez@...lia.com>)
- 2025/12/04 #2:
CVE-2025-66516: Apache Tika core, Apache Tika parsers, Apache Tika
PDF parser module: Update to CVE-2025-54988 to expand scop… (Tim Allison <tallison@...che.org>)
- 2025/12/04 #1:
CVE-2025-53960: Apache StreamPark: Use the user’s password as the secret key Vulnerability (Huajie Wang <benjobs@...che.org>)
- 2025/12/03 #8:
Re: libpng 1.6.52: Out-of-bounds vulnerability fixed:
CVE-2025-66293 (Greg Roelofs <roelofs@...ix.com>)
- 2025/12/03 #7:
Re: libpng 1.6.52: Out-of-bounds vulnerability fixed: CVE-2025-66293 (Cosmin Truta <ctruta@...il.com>)
- 2025/12/03 #6:
Re: libpng 1.6.52: Out-of-bounds vulnerability fixed:
CVE-2025-66293 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/03 #5:
libpng 1.6.52: Out-of-bounds vulnerability fixed: CVE-2025-66293 (Cosmin Truta <ctruta@...il.com>)
- 2025/12/03 #4:
CVE-2025-55182: RCE in React Server Components (Jan Schaumann <jschauma@...meister.org>)
- 2025/12/03 #3:
Re: 5 CVE's fixed in Fluent Bit (Christian Fischer <christian.fischer@...enbone.net>)
- 2025/12/03 #2:
Re: Questionable CVE's reported against dnsmasq (Christian Fischer <christian.fischer@...enbone.net>)
- 2025/12/03 #1:
FW: X.Org Security Advisory: multiple security issues in xkbcomp (Peter Hutterer <peter.hutterer@...-t.net>)
- 2025/12/02 #5:
[vim-security] A Windows uncontrolled search path vulnerability
affects Vim < 9.1.1947 (Christian Brabandt <cb@...bit.org>)
- 2025/12/02 #4:
Re: 5 CVE's fixed in Fluent Bit (Christian Brabandt <cb@...bit.org>)
- 2025/12/02 #3:
Django CVE-2025-13372 and CVE-2025-64460 (Natalia Bidart <nataliabidart@...ngoproject.com>)
- 2025/12/02 #2:
Re: 5 CVE's fixed in Fluent Bit (Christian Fischer <christian.fischer@...enbone.net>)
- 2025/12/02 #1:
expat looking for help with another unfixed non-public
denial-of-service vulnerability [CVE-2025-66382] (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/01 #6:
Re: 5 CVE's fixed in Fluent Bit (Christian Brabandt <cb@...bit.org>)
- 2025/12/01 #5:
CVE-2025-12183 in lz4-java, fixed in new fork (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/12/01 #4:
[kubernetes] CVE-2025-13281: Portworx Half-Blind SSRF in kube-controller-manager (Nathan Herz <nathan.herz97@...il.com>)
- 2025/12/01 #3:
WebKitGTK and WPE WebKit Security Advisory WSA-2025-0008 (Adrian Perez de Castro <aperez@...lia.com>)
- 2025/12/01 #2:
CVE-2025-64775: Apache Struts: File leak in multipart request
processing causes disk exhaustion (DoS) - S2-068 (Lukasz Lenart <lukaszlenart@...che.org>)
- 2025/12/01 #1:
CVE-2025-59789: Apache bRPC: Stack Exhaustion via Unbounded
Recursion in JSON Parser (Wang Weibing <wwbmmm@...che.org>)
- 2025/11/28 #3:
CVE-2025-59792: Apache Kvrocks: MONITOR command reveals plaintext
credentials to non-admins (Hulk Lin <hulk@...che.org>)
- 2025/11/28 #2:
CVE-2025-59790: Apache Kvrocks: RESET command grants admin
privileges (Hulk Lin <hulk@...che.org>)
- 2025/11/28 #1:
CVE-2023-48796: Apache DolphinScheduler: Sensitive information
disclosure (Lidong Dai <lidongdai@...che.org>)
- 2025/11/27 #5:
CVE-2025-61915 cups: Local denial-of-service via cupsd.conf update
and related issues (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/27 #4:
CVE-2025-58436 cups: Slow client communication leads to a possible
DoS attack (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/27 #3:
CVE-2025-59454: Apache CloudStack: Lack of user permission
validation leading to data leak for few APIs (Harikrishna Patnala <harikrishna@...che.org>)
- 2025/11/27 #2:
CVE-2025-59302: Apache CloudStack: Potential remote code execution
on Javascript engine defined rules (Harikrishna Patnala <harikrishna@...che.org>)
- 2025/11/27 #1:
CVE-2025-54057: Apache SkyWalking: Stored XSS vulnerability (Zhenxu Ke <kezhenxu94@...che.org>)
- 2025/11/26 #4:
Unbound: 1.24.2 addresses CVE-2025-11411 (again) (Yorgos Thessalonikefs <yorgos@...etlabs.nl>)
- 2025/11/26 #3:
CVE-2025-62728: Apache Hive: SQL injection vulnerability when
processing delete column statistics requests via the HMS … (Stamatis Zampetakis <zabetak@...che.org…)
- 2025/11/26 #2:
5 CVE's fixed in Fluent Bit (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/26 #1:
CVE-2025-59390: Apache Druid: Kerberos authenticaton chooses a
cryptographically unsecure secret if not configured explicitly. (Karan Kumar <karan@...che.org>)
- 2025/11/24 #1:
CVE-2025-65998: Apache Syncope: Default AES key used for internal
password encryption (Francesco Chicchiriccò <ilgrosso@...che.org>)
- 2025/11/22 #1:
libpng 1.6.51: Four buffer overflow vulnerabilities fixed:
CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, CVE-2025-65018 (Cosmin Truta <ctruta@...il.com>)
- 2025/11/20 #2:
gnutls 3.8.11 released with fix for CVE-2025-9820 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/20 #1:
CVE-2025-64524 cups-filters: Heap Buffer Overflow in rastertopclx
Filter Leading to Potential Arbitrary Code Execution (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/19 #1:
CVE-2025-64408: Apache Causeway: Java deserialization vulnerability
to authenticated attackers (Dan Haywood <danhaywood@...che.org>)
- 2025/11/18 #10:
Re: SQLite - Integer Overflow in FTS5 Extension
[CVE-2025-7709] ("John Hein" <josec-ml0@...mail.com>)
- 2025/11/18 #9:
[SECURITY PATCH 8/8] commands/usbtest: Ensure string length is sufficient in usb string processing (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #8:
[SECURITY PATCH 7/8] commands/usbtest: Use correct string length field (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #7:
[SECURITY PATCH 6/8] tests/lib/functional_test: Unregister commands on module unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #6:
[SECURITY PATCH 5/8] normal/main: Unregister commands on module unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #5:
[SECURITY PATCH 4/8] gettext/gettext: Unregister gettext command on module unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #4:
[SECURITY PATCH 3/8] net/net: Unregister net_set_vlan command on unload (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #3:
[SECURITY PATCH 2/8] kern/file: Call grub_dl_unref() after fs->fs_close() (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #2:
[SECURITY PATCH 1/8] commands/test: Fix error in recursion depth calculation (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/18 #1:
[SECURITY PATCH 0/8] GRUB2 vulnerabilities - 2025/11/18 (Daniel Kiper <daniel.kiper@...cle.com>)
- 2025/11/17 #6:
[OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3
token endpoints can grant Keystone authorization (CVE-2… (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/17 #5:
Re: [OSSA-2025-002] OpenStack Keystone:
Unauthenticated access to EC2/S3 token endpoints can grant Keystone
authorization (… (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/17 #4:
lightdm-kde-greeter: Privilege Escalation from lightdm Service User
to root in KAuth Helper Service (CVE-2025-62876) (Matthias Gerstner <mgerstner@...e.de>)
- 2025/11/17 #3:
Re: CVE-2025-40300 / VMScape (Solar Designer <solar@...nwall.com>)
- 2025/11/17 #2:
Re: CVE-2025-40300 / VMScape (Bjoern Franke <bjo@...afweide.org>)
- 2025/11/17 #1:
GitGuardian GGShield SSL/TLS Verification Bypass (No CVE) (tanish saxena <tanish.saxena26@...il.com>)
- 2025/11/16 #1:
Re: [OSSA-2025-002] OpenStack Keystone:
Unauthenticated access to EC2/S3 token endpoints can grant Keystone
authorizat… (Salvatore Bonaccorso <carnil@...ian.org…)
- 2025/11/15 #1:
Re: Questionable CVE's reported against dnsmasq (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/14 #7:
PostgreSQL releases fixes for CVE-2025-12817 &
CVE-2025-12818 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/14 #6:
Re: CVE-2025-40300 / VMScape (Moritz Mühlenhoff <jmm@...til.org>)
- 2025/11/14 #5:
Re: Questionable CVE's reported against dnsmasq (Jeffrey Walton <noloader@...il.com>)
- 2025/11/14 #4:
Re: CVE-2025-40300 / VMScape (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/11/14 #3:
CVE-2025-40300 / VMScape (Bjoern Franke <bjo@...afweide.org>)
- 2025/11/14 #2:
Re: Questionable CVE's reported against dnsmasq (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/14 #1:
Re: Questionable CVE's reported against dnsmasq (Jacob Bachmeyer <jcb62281@...il.com>)
- 2025/11/13 #2:
Re: Questionable CVE's reported against dnsmasq (Alexander Patrakov <patrakov@...il.com>)
- 2025/11/13 #1:
Re: Questionable CVE's reported against dnsmasq (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/12 #2:
CVE-2025-64503 libcupsfilters, cups-filters 1.x: out of bounds write
in pdftoraster (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/12 #1:
CVE-2025-57812 libcupsfilters, cups-filters 1.x: Multiple
TIFF-related issues in libcupsfilters (Zdenek Dohnal <zdohnal@...hat.com>)
- 2025/11/11 #10:
CVE-2025-64407: Apache OpenOffice: URL fetching can be used to
exfiltrate arbitrary INI file values and environment variab… (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #9:
CVE-2025-64406: Apache OpenOffice: Possible memory corruption
during CSV import (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #8:
CVE-2025-64405: Apache OpenOffice: Remote documents loaded without
prompt via DDE function (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #7:
CVE-2025-64404: Apache OpenOffice: Remote documents loaded without
prompt via background and bullet images (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #6:
CVE-2025-64403: Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #5:
CVE-2025-64402: Apache OpenOffice: Remote documents loaded without
prompt via OLE objects (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #4:
CVE-2025-64401: Apache OpenOffice: Remote documents loaded without
prompt via IFrame (Arrigo Marchiori <ardovm@...che.org>)
- 2025/11/11 #3:
CVE-2024-47866 Ceph: RGW DoS via improper input validation. ("Sage [They / Them] McTaggart" <amctagga@...hat.com>)
- 2025/11/11 #2:
CVE-2025-61623: Apache OFBiz: Reflected Cross-site Scripting (Jacques Le Roux <jleroux@...che.org>)
- 2025/11/11 #1:
CVE-2025-59118: Apache OFBiz: Critical Remote Command Execution
via Unrestricted File Upload (Jacques Le Roux <jleroux@...che.org>)
- 2025/11/07 #2:
Re: runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 (Ali Polatel <alip@...sys.org>)
- 2025/11/07 #1:
Re: Becoming a CVE Naming Authority for your project (Peter Gutmann <pgut001@...auckland.ac.nz>)
- 2025/11/06 #6:
Re: Becoming a CVE Naming Authority for your project (Jeremy Stanley <fungi@...goth.org>)
- 2025/11/06 #5:
Re: Becoming a CVE Naming Authority for your project (Pat Gunn <pgunn01@...il.com>)
- 2025/11/06 #4:
Re: Becoming a CVE Naming Authority for your project ("Olle E. Johansson" <oej@...ina.net>)
- 2025/11/06 #3:
Re: Questionable CVE's reported against dnsmasq ("Olle E. Johansson" <oej@...ina.net>)
31765 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.