Overview
Description
Statistics
- 1 Post
Fediverse
Proof-of-concept for CVE-2025-48593: No, this Android Bluetooth issue does NOT affect your phone or tablet | Worth Doing Badly
https://worthdoingbadly.com/bluetooth/
Overview
- Artifex
- Ghostscript
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 2 Posts
Fediverse
Akamai patched CVE-2025-66373: the chunk-size ≠ chunk-data loophole that let smuggled requests ride “extra” bytes straight into origin. “Fixed Nov 17” is corp-speak for “it silently forwarded your traffic for 2 months.”
https://www.akamai.com/blog/security/2025/dec/cve-2025-66373-http-request-smuggling-chunked-body-size
Overview
Description
Statistics
- 1 Post
Overview
- Apache Software Foundation
- Apache Tika PDF parser module
- org.apache.tika:tika-parser-pdf-module
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
Perfect 10 XXE in Apache Tika tika-core. 🥳
https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. \n\nThis CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. \n\nFirst, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. \n\nSecond, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the \"org.apache.tika:tika-parsers\" module.
Overview
- Apache Software Foundation
- Apache Tika core
- org.apache.tika:tika-core
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
Perfect 10 XXE in Apache Tika tika-core. 🥳
https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. \n\nThis CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. \n\nFirst, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. \n\nSecond, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the \"org.apache.tika:tika-parsers\" module.
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
Description
Statistics
- 1 Post