OBS-Vigilance

TitleDescriptionDate
FortiOS: ingress filtrering bypass via SSH Trusted Hosts Bypassopen in new windowAn attacker can bypass filtering rules of FortiOS, via SSH Trusted Hosts Bypass, in order to send malicious data...Visit link for details
Google Android Pixel: multiple vulnerabilities of March 2025open in new windowAn attacker can use several vulnerabilities of Google Android Pixel...Visit link for details
Zabbix: information disclosure via problem.view.refreshopen in new windowAn attacker can bypass access restrictions to data of Zabbix, via problem.view.Visit link for details
Zabbix: executing DLL code via OpenSSL Configuration Fileopen in new windowAn attacker can create a malicious DLL for Zabbix, via OpenSSL Configuration File, and then put it in the current directory, in order to execute code...Visit link for details
QEMU: use after free via QIOChannelWebsockopen in new windowAn attacker, in a guest system, can force the reuse of a freed memory area of QEMU, via QIOChannelWebsock, in order to trigger a denial of service, and possibly to run code...Visit link for details
Redis: four vulnerabilities dated 03/10/2025open in new windowAn attacker can use several vulnerabilities of Redis, dated 03/10/2025...Visit link for details
MIME4J: write access via MIME Messages Headers Injectionopen in new windowAn attacker can bypass access restrictions of MIME4J, via MIME Messages Headers Injection, in order to alter data...Visit link for details
Apache Commons Configuration: overload via Usage Patternsopen in new windowAn attacker can trigger an overload of Apache Commons Configuration, via Usage Patterns, in order to trigger a denial of service...Visit link for details
Rust astral-tokio-tar: directory traversal via Entry::unpack_in_raw()open in new windowAn attacker can traverse directories of Rust astral-tokio-tar, via Entry::unpack_in_Visit link for details
Linux kernel: multiple vulnerabilities dated 02/10/2025open in new windowAn attacker can use several vulnerabilities of the Linux kernel, dated 02/10/2025...Visit link for details