Overview
Description
Statistics
- 3 Posts
Fediverse
Bluesky
Overview
- Meta
- react-server-dom-webpack
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
We've released Netty 4.2.9 and 4.1.130.
They fix CVE-2025-67735 (https://github.com/netty/netty/security/advisories/GHSA-84h7-rjj3-6jx4), which is a line break injection vulnerability when encoding HTTP request objects.
The fix introduced a regression we had to fix as well, so versions 4.2.8 and 4.1.129 are skipped.
https://netty.io/news/2025/12/15/4-2-9.html
https://netty.io/news/2025/12/15/4-2-8.html
https://netty.io/news/2025/12/15/4-1-130-Final.html
https://netty.io/news/2025/12/15/4-1-129-Final.html
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
Oh that could be fun.
https://www.cve.org/CVERecord?id=CVE-2025-67809
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
A privilege escalation in Dropbear (CVE-2025-14282) allows any authenticated user to run arbitrary commands as root. The vulnerability affects versions 2024.84 to 2025.88. Dropbear release 2025.89 fixes the vulnerability.
A mitigation is to run dropbear without unix socket forwarding by adding the -j option.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- notepad-plus-plus
- notepad-plus-plus
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
⚠️ CVE-2025-14252: Advantech SUSI driver (≤5.0.24335) has HIGH-severity improper access control. Local attackers can escalate privileges & execute arbitrary code—industrial systems are at risk. Restrict access & monitor activity! https://radar.offseq.com/threat/cve-2025-14252-vulnerability-in-advantech-susi-cdc40913 #OffSeq #Vuln #ICS