A huge collection of 3400+ free website templates JAR theme com WP themes and more at the biggest community-driven free web design site
Home / admin

admin

Remote Code Execution vulnerability in Spring Cloud Data Flow (CVE-2024-37084)

Advisory No: TZCERT/SA/2024/07/26-6 Date of First Release: 26th July 2024 Source: Spring Software Affected: Spring Cloud Data Flow Overview: Spring is vulnerable to a remote code vulnerability. The attackers can leverage the vulnerability to compromise the server. Description: Spring Cloud Data Flow, a microservices-based streaming in Cloud Foundry and Kubernetes …

Read More »

Multiple critical vulnerabilities affecting Dell EMC Avamar, Dell Protection Advisor, Dell VxRail, and Dell RecoverPoint

Advisory No: TZCERT/SA/2024/07/26-5 Date of First Release: 26th July 2024 Source: Dell Software Affected: Dell EMC, Dell Protection Advisor, Dell VxRail, Dell RecoverPoint Overview: Dell products are vulnerable to multiple critical vulnerabilities. Exploitation of these vulnerabilities may allow attackers to execute arbitrary code on affected devices. Description: Multiple third-party components …

Read More »

Authenticated Remote Command Execution in D-Link DIR-823X

Advisory No: TZCERT/SA/2024/07/26-4 Date of First Release: 26th July 2024 Source: D-Link Software Affected: DIR-823X – Firmware v240126 Overview: The firmware version in the D-Link device is vulnerable to a remote command execution vulnerability. The attackers can leverage the vulnerability to take control of the affected device. Description: DIR-823X Hardware …

Read More »

A critical vulnerability in WordPress (CVE-2024-6636)

Advisory No: TZCERT/SA/2024/07/26-3 Date of First Release: 26th July 2024 Source: Wordfence Software Affected: woo-social-login Overview: WordPress is vulnerable to a critical vulnerability. Exploitation of this vulnerability makes it possible for unauthenticated privilege escalation. Description: WordPress plugin woo-social-login is affected by the vulnerability tracked as CVE-2024-6636 with CVSS score of …

Read More »

Critical Vulnerabilities in multiple IBM vulnerabilities (CVE-2020-13936, CVE-2023-36665, CVE-2020-15257)

Advisory No: TZCERT/SA/2024/07/26-2 Date of First Release: 26th July 2024 Source: IBM Software Affected:  Apache Velocity, protobuf.js, Containerd Overview: Multiple IBM products depending on Apache Velocity, protobuf.js, Containerd are vulnerable to critical vulnerabilities. Attackers can exploit the vulnerabilities to execute arbitrary code on the affected system. Description: Multiple IBM products …

Read More »

Out-of-Bounds Write Vulnerability in HPE ProLiant DL/ML/SY/XL and Alletra Servers, (CVE-2021-38578)

Advisory No: TZCERT/SA/2024/07/26-1 Date of First Release: 26th July 2024 Source: Hewlett-Packard (HP) Software Affected:  HPE ProLiant DL/ML/SY/XL, Alletra Servers, HPE Synergy, HPE Edgeline, HPE Compute Edge Server Overview: HPE ProLiant DL/ML/SY/XL, Alletra Servers, HPE Synergy, HPE Edgeline, and HPE Compute Edge Server are vulnerable to critical severity vulnerability. The …

Read More »

TZCERT-SU-24-0805 (Ubuntu Security Update)

Ubuntu has released security updates to address vulnerabilities in python-zipp, poppler, OCS Inventory, phpCAS and provd. Exploitation of these vulnerabilities may allow an attacker to cause denial of service condition. Users and administrators are encouraged to review Ubuntu Security Advisories USN-6906-1, USN-6915-1, USN-6914-1, USN-6913-1, and USN-6912-1 and apply necessary updates.

Read More »

TZCERT-SU-24-0804 (Broadcom Security Update)

Broadcom has released security updates to address vulnerabilities in VMware ESXi, vCenter Server, and VMware Tanzu. Exploitation of these vulnerabilities may allow an attacker to cause a denial of service condition. Users and administrators are encouraged to review Broadcom Security Advisories SecurityAdvisories-24505 and security-advisory-tanzu and apply necessary updates.

Read More »

TZCERT-SU-24-0803 (Oracle Linux Security Update)

Oracle has released security updates to address vulnerabilities in multiple Oracle Products. Exploitation of these vulnerabilities may allow an attacker to take control of affected system. Users and administrators are encouraged to review Oracle Security Advisories cpujul2024, ELSA-2024-4761 and ELSA-2024-4749 and apply necessary updates.

Read More »

TZCERT-SU-24-0802 (Chrome Security Update)

Google has released security updates to address vulnerabilities in Chrome for iOS and Chrome for Android. Exploitation of these vulnerabilities may allow an attacker to take control of affected system. Users and administrators are encouraged to review Chrome Security Advisories chrome-for-ios and chrome-for-android and apply necessary updates.

Read More »