[<prev month] [next month>] [year] [list]
oss-security mailing list - 2022/11
Mon | Tue | Wed | Thu | Fri | Sat | Sun
|
---|
| 1 24 | 2 15 | 3 11 | 4 9 | 5 1 | 6
|
7 2 | 8 2 | 9 | 10 5 | 11 | 12 | 13
|
14 5 | 15 4 | 16 1 | 17 | 18 1 | 19 | 20
|
21 7 | 22 | 23 1 | 24 1 | 25 | 26 | 27
|
28 | 29 4 | 30 2 |
|
Messages by day:
November 1 (24 messages)
- Re: Is third party javascript on a login page considered
dangerous? (Jan Engelhardt <jengelh@...i.de>)
- CVE-2022-31764: Apache ShardingSphere ElasticJob-UI allows RCE via
event trace data source JDBC (Weijie Wu <wuweijie@...che.org>)
- Xen Security Advisory 412 v2 (CVE-2022-42327) - x86: unintended
memory sharing between guests (Xen.org security team <security@....org>)
- Xen Security Advisory 414 v2 (CVE-2022-42309) - Xenstore: Guests
can crash xenstored (Xen.org security team <security@....org>)
- Xen Security Advisory 415 v2 (CVE-2022-42310) - Xenstore: Guests
can create orphaned Xenstore nodes (Xen.org security team <security@....org>)
- Xen Security Advisory 416 v2 (CVE-2022-42319) - Xenstore: Guests
can cause Xenstore to not free temporary memory (Xen.org security team <security@....org>)
- Xen Security Advisory 417 v2 (CVE-2022-42320) - Xenstore: Guests
can get access to Xenstore nodes of deleted domains (Xen.org security team <security@....org>)
- Xen Security Advisory 418 v2 (CVE-2022-42321) - Xenstore: Guests
can crash xenstored via exhausting the stack (Xen.org security team <security@....org>)
- Xen Security Advisory 419 v2 (CVE-2022-42322,CVE-2022-42323) -
Xenstore: Cooperating guests can create arbitrary number… (Xen.org security team <security@....org…)
- Xen Security Advisory 420 v2 (CVE-2022-42324) - Oxenstored 32->31
bit integer truncation issues (Xen.org security team <security@....org>)
- Xen Security Advisory 421 v2 (CVE-2022-42325,CVE-2022-42326) -
Xenstore: Guests can create arbitrary number of nodes vi… (Xen.org security team <security@....org…)
- Re: Is third party javascript on a login page considered dangerous? (Solar Designer <solar@...nwall.com>)
- CVE-2022-34662: Apache DolphinScheduler prior to 3.0.0 allows path
traversal (Jiajie Zhong <zhongjiajie@...che.org>)
- CVE-2022-31777: Apache Spark XSS vulnerability in log viewer UI
Javascript ("Sean R. Owen" <srowen@...che.org>)
- OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE… (Solar Designer <solar@...nwall.com>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Ove… (Demi Marie Obenour <demi@...isiblething…)
- Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow
(CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow
… (Dave Horsfall <dave@...sfall.org>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow
(CVE-2022-3602), X.509 Email Address Variable Length Buffer Over… (Pavan Maddamsetti <pavan.maddamsetti@gm…)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Ove… (Demi Marie Obenour <demi@...isiblething…)
- Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow
(CVE-2022-3602), X.509 Email Address Variable Length Buffer Overf… ("Erin Shepherd" <erin.shepherd@....eu>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow
(CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow… (Jeffrey Walton <noloader@...il.com>)
- CVE-2022-43982: Apache Airflow: Reflected XSS via Origin Query
Argument in URL (Jedidiah Cunningham <jedcunningham@...che.org>)
- CVE-2022-43985: Apache Airflow: Open Redirect (Jedidiah Cunningham <jedcunningham@...che.org>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Overflow (CVE-2022-3786) (alex@...xburke.ca)
November 2 (15 messages)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Ove… (Demi Marie Obenour <demi@...isiblething…)
- Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow
(CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow… (Alex Gaynor <alex.gaynor@...il.com>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Ove… (Demi Marie Obenour <demi@...isiblething…)
- Fwd: Node.js security updates for all active release lines,
November 2022 ("soyjuanarbol@...il.com" <soyjuanarbol@...il.com>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Overflow (CVE-202… ("alice" <alice@...ya.dev>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Overflow (CVE-202… ("alice" <alice@...ya.dev>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow
(CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow
(… (Tavis Ormandy <taviso@...il.com>)
- CVE-2022-43670: Apache Sling App CMS: XSS in Sling CMS Reference App
Taxonomy Path (Daniel Klco <dklco@...che.org>)
- Re: Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Over… (Alex Gaynor <alex.gaynor@...il.com>)
- Re: Fwd: Node.js security updates for all active
release lines, November 2022 (Jan Schaumann <jschauma@...meister.org>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Overflow (CVE… (Hanno Böck <hanno@...eck.de>)
- Re: Re: OpenSSL X.509 Email Address 4-byte
Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
O… (Steffen Nurpmeso <steffen@...oden.eu>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow
(CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow
(… (Tavis Ormandy <taviso@...il.com>)
- Re: Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Over… (Alex Gaynor <alex.gaynor@...il.com>)
- Re: OpenSSL X.509 Email Address 4-byte Buffer
Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer
Overflow (CVE… (Kurt H Maier <khm@...ops.net>)
November 3 (11 messages)
November 4 (9 messages)
November 5 (1 message)
November 7 (2 messages)
November 8 (2 messages)
November 10 (5 messages)
November 14 (5 messages)
November 15 (4 messages)
November 16 (1 message)
November 18 (1 message)
November 21 (7 messages)
November 23 (1 message)
November 24 (1 message)
November 29 (4 messages)
November 30 (2 messages)
95 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.