oss-security mailing list
Recent messages:
- 2025/04/29 #1:
PowerDNS Security Advisory 2025-02: Denial of service via crafted DoH
exchange (Remi Gacogne <remi.gacogne@...erdns.com>)
- 2025/04/28 #3:
CVE-2025-31651: Apache Tomcat: Bypass of rules in Rewrite Valve (Mark Thomas <markt@...che.org>)
- 2025/04/28 #2:
CVE-2025-31650: Apache Tomcat: DoS via malformed HTTP/2
PRIORITY_UPDATE frame (Mark Thomas <markt@...che.org>)
- 2025/04/28 #1:
Re: Re: Trailing dot in Cygwin filenames [was:
failed to clone iptables,ipset,nftables] (Werner Koch <wk@...pg.org>)
- 2025/04/25 #7:
Re: vulnerabilities in busybox tar and cpio tools (Demi Marie Obenour <demiobenour@...il.com>)
- 2025/04/25 #6:
Re: CVE-2024-56431: libtheora: incorrect bitwise shift in huffdec.c (Solar Designer <solar@...nwall.com>)
- 2025/04/25 #5:
Re: Trailing dot in Cygwin filenames [was: failed to clone
iptables,ipset,nftables] (Jan Engelhardt <ej@...i.de>)
- 2025/04/25 #4:
CVE-2024-56431: libtheora: incorrect bitwise shift in huffdec.c ("xiaolin" <dongxiaolin@...pin.org>)
- 2025/04/25 #3:
CVE-2024-56430: openfhe: OpenFHE through 1.2.3 has a NULL pointer dereference bug ("xiaolin" <dongxiaolin@...pin.org>)
- 2025/04/25 #2:
Re: CVE-2025-3512: Qt Base QTextMarkdownImporter Front
Matter Buffer Overflow (Jacob Bachmeyer <jcb62281@...il.com>)
- 2025/04/25 #1:
Re: CVE-2025-3512: Qt Base QTextMarkdownImporter Front Matter Buffer Overflow (Solar Designer <solar@...nwall.com>)
- 2025/04/24 #9:
Re: vulnerabilities in busybox tar and cpio tools (Solar Designer <solar@...nwall.com>)
- 2025/04/24 #8:
Re: vulnerabilities in busybox tar and cpio tools (Demi Marie Obenour <demiobenour@...il.com>)
- 2025/04/24 #7:
Re: CVE-2025-0395: Buffer overflow in the GNU C
Library's assert() (Qualys Security Advisory <qsa@...lys.com>)
- 2025/04/24 #6:
Re: CVE-2025-3512: Qt Base QTextMarkdownImporter
Front Matter Buffer Overflow (Jakub Wilk <jwilk@...lk.net>)
- 2025/04/24 #5:
Re: CVE-2025-3512: Qt Base QTextMarkdownImporter Front Matter Buffer Overflow (Solar Designer <solar@...nwall.com>)
- 2025/04/24 #4:
CVE-2025-3512: Qt Base QTextMarkdownImporter Front Matter Buffer Overflow ("田世林" <tianshilin@...pin.org>)
- 2025/04/24 #3:
Re: [EXTERNAL] Re: vulnerabilities in busybox tar and
cpio tools (Ian Norton <Ian.Norton@...rust.com>)
- 2025/04/24 #2:
Re: [EXTERNAL] Re: vulnerabilities in busybox tar and
cpio tools (Ian Norton <Ian.Norton@...rust.com>)
- 2025/04/24 #1:
Re: vulnerabilities in busybox tar and cpio tools (Albert Veli <albert.veli@...il.com>)
- 2025/04/23 #6:
Re: vulnerabilities in busybox tar and cpio tools (Salvatore Bonaccorso <carnil@...ian.org>)
- 2025/04/23 #5:
Re: vulnerabilities in busybox tar and cpio tools (Salvatore Bonaccorso <carnil@...ian.org>)
- 2025/04/23 #4:
CVE-2025-23016: Integer & buffer overflow in fastcgi <
2.4.5 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/23 #3:
Re: vulnerabilities in busybox tar and cpio tools (Jakub Wilk <jwilk@...lk.net>)
- 2025/04/23 #2:
Re: vulnerabilities in busybox tar and cpio tools (Ricardo Branco <rbranco@...e.de>)
- 2025/04/23 #1:
vulnerabilities in busybox tar and cpio tools (Ian Norton <Ian.Norton@...rust.com>)
- 2025/04/22 #1:
CVE-2025-26413: Apache Kvrocks: The server was crashed by the
negative offset (Hulk Lin <hulk@...che.org>)
- 2025/04/21 #7:
Re: 3 new CVE's in old branch of GNU mailman ("Jim P." <oss-security@....email>)
- 2025/04/21 #6:
Re: 3 new CVE's in old branch of GNU mailman (Russ Allbery <eagle@...ie.org>)
- 2025/04/21 #5:
Re: 3 new CVE's in old branch of GNU mailman (Valtteri Vuorikoski <vuori@...com.org>)
- 2025/04/21 #4:
Re: 3 new CVE's in old branch of GNU mailman (Mats Wichmann <mats@...hmann.us>)
- 2025/04/21 #3:
Re: 3 new CVE's in old branch of GNU mailman (Thomas Ward <teward@...mas-ward.net>)
- 2025/04/21 #2:
Re: 3 new CVE's in old branch of GNU mailman (Valtteri Vuorikoski <vuori@...com.org>)
- 2025/04/21 #1:
3 new CVE's in old branch of GNU mailman (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/19 #1:
Re: CVE-2025-32433: Unauthenticated Remote Code
Execution in Erlang/OTP SSH (Fabian Bäumer <fabian.baeumer@....de>)
- 2025/04/18 #6:
Re: CVE-2025-32433: Unauthenticated Remote Code Execution in Erlang/OTP SSH (Solar Designer <solar@...nwall.com>)
- 2025/04/18 #5:
libarchive 3.7.8 fixed CVE-2024-57970, CVE-2025-1632,
& CVE-2025-25724 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/18 #4:
A bowlful of bugs in GNOME's libsoup (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/18 #3:
CVE-2025-29953: Apache ActiveMQ NMS OpenWire Client:
deserialization allowlist bypass (Arnout Engelen <engelen@...che.org>)
- 2025/04/18 #2:
Re: CVE-2025-32433: Unauthenticated Remote Code
Execution in Erlang/OTP SSH (Fabian Bäumer <fabian.baeumer@....de>)
- 2025/04/18 #1:
Re: CVE-2025-32433: Unauthenticated Remote Code Execution in Erlang/OTP SSH (Solar Designer <solar@...nwall.com>)
- 2025/04/17 #5:
Re: Multiple vulnerabilities in libxml2 (Nick Wellnhofer <wellnhofer@...um.de>)
- 2025/04/17 #4:
Re: Multiple vulnerabilities in libxml2 (Solar Designer <solar@...nwall.com>)
- 2025/04/17 #3:
Multiple vulnerabilities in libxml2 (Nick Wellnhofer <wellnhofer@...um.de>)
- 2025/04/17 #2:
Re: CVE program averts swift end (Jan Klopper <janklopper@...erheight.com>)
- 2025/04/17 #1:
Re: CVE program averts swift end ("Olle E. Johansson" <oej@...ina.net>)
- 2025/04/16 #6:
Re: CVE program averts swift end (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/16 #5:
Re: CVE program averts swift end (Brian Behlendorf <brian@...lendorf.com>)
- 2025/04/16 #4:
Re: CVE program averts swift end (Marco Moock <mm@...fdsl.de>)
- 2025/04/16 #3:
CVE program averts swift end (Rolf Reintjes <rolf.reintjes@....de>)
- 2025/04/16 #2:
CVE-2025-32433: Unauthenticated Remote Code Execution in Erlang/OTP
SSH (Fabian Bäumer <fabian.baeumer@....de>)
- 2025/04/16 #1:
CVE-2024-56736: Apache HertzBeat (incubating): Server-Side Request
Forgery (SSRF) in Api Config Oss (Chao Gong <gongchao@...che.org>)
- 2025/04/13 #5:
Re: CVE-2024-56406: Perl 5.34, 5.36, 5.38 and 5.40
are vulnerable to a heap buffer overflow when transliterating non-ASCII
bytes (Stig Palmquist <stig@...g.io>)
- 2025/04/13 #4:
Re: CVE-2024-56406: Perl 5.34, 5.36, 5.38 and 5.40 are vulnerable to a heap buffer overflow when transliterating non-ASCII b… (Solar Designer <solar@...nwall.com>)
- 2025/04/13 #3:
CVE-2024-56406: Perl 5.34, 5.36, 5.38 and 5.40 are vulnerable to a
heap buffer overflow when transliterating non-ASCII bytes (Stig Palmquist <stig@...g.io>)
- 2025/04/13 #2:
Re: Security audit of PHP (Solar Designer <solar@...nwall.com>)
- 2025/04/13 #1:
Re: CVE-2025-0395: Buffer overflow in the GNU C Library's assert() (Solar Designer <solar@...nwall.com>)
- 2025/04/12 #2:
Security audit of PHP (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/12 #1:
CVE-2025-32896: Apache SeaTunnel: Unauthenticated insecure access (Hailin Wang <wanghailin@...che.org>)
- 2025/04/11 #1:
CVE-2025-24859: Apache Roller: Insufficient Session Expiration on
Password Change ("David M. Johnson" <snoopdave@...che.org>)
- 2025/04/10 #6:
Re: CVE-2024-50217: Linux kernel: btrfs:
Use-after-free of block device file in __btrfs_free_extra_devids() (Demi Marie Obenour <demiobenour@...il.com>)
- 2025/04/10 #5:
Re: CVE-2024-50217: Linux kernel: btrfs:
Use-after-free of block device file in __btrfs_free_extra_devids() (Greg KH <gregkh@...uxfoundation.org>)
- 2025/04/10 #4:
CVE-2024-50217: Linux kernel: btrfs: Use-after-free of block device file in __btrfs_free_extra_devids() ("akendo@...ndo.eu" <akendo@...ndo.eu>)
- 2025/04/10 #3:
Re: CVE-2025-29868: Apache Answer: Using externally
referenced images can leak user privacy. (LinkinStar <linkinstar@...che.org>)
- 2025/04/10 #2:
Vulnerabilities in Jenkins Docker images (Daniel Beck <ml@...kweb.net>)
- 2025/04/10 #1:
Re: CVE-2025-31344: giflib: The giflib open-source
component has a buffer overflow vulnerability. (Sebastian Pipping <sebastian@...ping.org>)
- 2025/04/09 #7:
Re: CVE-2025-31344: giflib: The giflib open-source component has a buffer
overflow vulnerability. (Bernhard Rosenkränzer <bero@...dev.ch>)
- 2025/04/09 #6:
Re: Announce: OpenSSH 10.0 released (Damien Miller <djm@....openbsd.org>)
- 2025/04/09 #5:
Re: CVE-2025-31344: giflib: The giflib open-source
component has a buffer overflow vulnerability. (Sebastian Pipping <sebastian@...ping.org>)
- 2025/04/09 #4:
xmlrpc-c bundles a (very old and) vulnerable copy of libexpat (Sebastian Pipping <sebastian@...ping.org>)
- 2025/04/09 #3:
CVE-2025-27391: Apache ActiveMQ Artemis: Passwords leaking from
broker properties in the debug log (Domenico Francesco Bruscino <brusdev@...che.org>)
- 2025/04/09 #2:
CVE-2025-30677: Apache Pulsar IO Kafka Connector, Apache Pulsar IO
Kafka Connect Adaptor: Sensitive information logged in Puls… (Lari Hotari <lhotari@...che.org>)
- 2025/04/09 #1:
Announce: OpenSSH 10.0 released (Damien Miller <djm@....openbsd.org>)
- 2025/04/08 #5:
CVE-2025-30215: nats-server: Missing access controls for JS API (Phil Pennock <oss-security-phil@...dhuis.org>)
- 2025/04/08 #4:
Re: Xen Security Notice 2 (CVE-2024-35347) AMD CPU
Microcode Signature Verification Vulnerability (Andrew Cooper <andrew.cooper3@...rix.com>)
- 2025/04/08 #3:
CVE-2025-31498: c-ares use-after-free (Brad House <brad@...d-house.com>)
- 2025/04/08 #2:
CVE-2025-31672: Apache POI: parsing OOXML based files (xlsx, docx,
etc.), poi-ooxml could read unexpected data if underlying … (PJ Fanning <fanningpj@...che.org>)
- 2025/04/08 #1:
Re: CVE-2025-31344: giflib: The giflib open-source component has a buffer overflow vulnerability. (李亚杰 <liyajie@...neuler.sh>)
- 2025/04/07 #6:
Re: CVE-2025-31344: giflib: The giflib open-source component has a buffer
overflow vulnerability. (Bernhard Rosenkränzer <bero@...dev.ch>)
- 2025/04/07 #5:
Re: CVE-2025-31344: giflib: The giflib open-source
component has a buffer overflow vulnerability. (Hanno Böck <hanno@...eck.de>)
- 2025/04/07 #4:
Re: CVE-2025-31344: giflib: The giflib open-source
component has a buffer overflow vulnerability. (Mingcong Bai <jeffbai@...c.io>)
- 2025/04/07 #3:
CVE-2025-31344: giflib: The giflib open-source component has a buffer overflow vulnerability. (李亚杰 <liyajie@...neuler.sh>)
- 2025/04/07 #2:
WebKitGTK and WPE WebKit Security Advisory WSA-2025-0003 (Adrian Perez de Castro <aperez@...lia.com>)
- 2025/04/07 #1:
PowerDNS Recursor Security Advisory 2025-01 regarding PowerDNS
Recusor 5.2.0 (Otto Moerbeek <otto.moerbeek@...erdns.com>)
- 2025/04/06 #3:
Re: CVE-2025-30473: Apache Airflow Common SQL
Provider: Remote Code Execution via Sql Injection (Jeffrey Walton <noloader@...il.com>)
- 2025/04/06 #2:
Re: CVE-2025-30473: Apache Airflow Common SQL Provider: Remote Code Execution via Sql Injection (Solar Designer <solar@...nwall.com>)
- 2025/04/06 #1:
Re: CVE-2025-30473: Apache Airflow Common SQL
Provider: Remote Code Execution via Sql Injection (Hanno Böck <hanno@...eck.de>)
- 2025/04/04 #4:
CVE-2025-22871 : Go net/http: request smuggling
through invalid chunked data (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/04 #3:
pgAdmin 4 v9.2 fixes CVE-2025-2945 & CVE-2025-2946 (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/04 #2:
CVE-2025-30473: Apache Airflow Common SQL Provider: Remote Code
Execution via Sql Injection (Elad Kalif <eladkal@...che.org>)
- 2025/04/04 #1:
CVE-2025-3155 GNOME Yelp: Arbitrary file read by
abusing ghelp scheme (Alan Coopersmith <alan.coopersmith@...cle.com>)
- 2025/04/03 #3:
Re: XZ Utils: Threaded decoder frees memory too
early (CVE-2025-31115) (Sam James <sam@...too.org>)
- 2025/04/03 #2:
Re: XZ Utils: Threaded decoder frees memory too early (CVE-2025-31115) (Sam James <sam@...too.org>)
- 2025/04/03 #1:
XZ Utils: Threaded decoder frees memory too early (CVE-2025-31115) (Sam James <sam@...too.org>)
- 2025/04/02 #5:
CVE-2025-2704 - OpenVPN 2.6.1 through 2.6.13 with possible DoS (David Sommerseth <dazo@...ephia.org>)
- 2025/04/02 #4:
[ANNOUNCE] ATS is vulnerable to request smuggling via chunked messages (Masakazu Kitajo <maskit@...che.org>)
- 2025/04/02 #3:
Multiple vulnerabilities in Jenkins and Jenkins plugins (Kevin Guerroudj <kguerroudj@...udbees.com>)
- 2025/04/02 #2:
CVE-2025-27556: Django: Potential DoS in LoginView, LogoutView, and set_language() on Windows (Natalia Bidart <nataliabidart@...ngoproject.com>)
- 2025/04/02 #1:
Re: CVE-2025-29868: Apache Answer: Using externally
referenced images can leak user privacy. (Jacob Bachmeyer <jcb62281@...il.com>)
- 2025/04/01 #6:
Re: Linux kernel: CVE-2024-57882 fix did not prevent data stream corruption in the MPTCP protocol (Solar Designer <solar@...nwall.com>)
31064 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.