[UPDATE] [mittel] NoMachine: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in NoMachine ausnutzen, um Dateien zu manipulieren, und um seine Privilegien zu erhöhen.
BSI CERT Security Advisory
*** GMail and Validation-Mails *** There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
Ein Angreifer kann mehrere Schwachstellen in NoMachine ausnutzen, um Dateien zu manipulieren, und um seine Privilegien zu erhöhen.
BSI CERT Security Advisory
Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsmaßnahmen zu umgehen und Informationen offenzulegen.
BSI CERT Security Advisory
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM WebSphere Application Server Liberty ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen und Informationen offenzulege…
BSI CERT Security Advisory
Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um unter anderem einen Denial of Service-Angriff auszuführen oder um Sicherheitsmechanismen zu umgehen.
BSI CERT Security Advisory
Ein Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder HTTP-Request-Smuggling zu erreichen, was weitere Angriffe erm…
BSI CERT Security Advisory
Ein lokaler oder entfernter, anonymer Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um einen Denial of Service Angriff durchzuführen.
BSI CERT Security Advisory
Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Informationen offenzulegen.
BSI CERT Security Advisory
Ein Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-o…
BSI CERT Security Advisory
A vulnerability was found in Flowring Technology Corp Agentflow. It has been classified as critical. The affected element is an unknown function of the file /WebAgenda/SMBAjaxAutoComplete.do of the component Ajax Auto C…
vuldb
A vulnerability was found in Octopus Deploy Octopus Server up to 2026.1.11780/2026.2.13440/2026.3.15828 and classified as critical. Impacted is an unknown function. The manipulation results in deserialization. This vuln…
vuldb
Ein Angreifer kann mehrere Schwachstellen in X.Org X11 ausnutzen, um einen Denial of Service Angriff durchzuführen.
BSI CERT Security Advisory
Ein Angreifer kann mehrere Schwachstellen in Fleet ausnutzen, um erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand auszul…
BSI CERT Security Advisory
A vulnerability has been found in Dassault Systèmes GEOVIA Geospatial Data Manager R2024x/R2026x and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. This vul…
vuldb
Ein lokaler Angreifer kann eine Schwachstelle in NoMachine ausnutzen, um möglicherweise beliebigen Code auszuführen, Daten offenzulegen oder zu verändern oder andere, nicht näher genannte Auswirkungen zu erreichen. Eine…
BSI CERT Security Advisory
A vulnerability, which was classified as problematic, was found in Progress Telerik Fiddler Everywhere up to 8.1.x. This vulnerability affects unknown code of the component Fiddler.WebUi. Executing a manipulation can le…
vuldb
A vulnerability, which was classified as problematic, has been found in Progress Telerik Fiddler Everywhere up to 8.1.x. This affects an unknown part. Performing a manipulation results in improper authorization. This vu…
vuldb
Ein Angreifer kann mehrere Schwachstellen in Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia and Safari ausnutzen,, um beliebigen Code mit Root- oder Kernel-Rechten auszuführen, Berechtigungen zu erweit…
BSI CERT Security Advisory
A vulnerability classified as critical was found in Red Hat Enterprise Linux. Affected by this issue is the function kill of the component Namespace. Such manipulation leads to denial of service. This vulnerability is d…
vuldb
A vulnerability classified as critical has been found in ljharb shell-quote up to 1.10.x. Affected by this vulnerability is the function quote. This manipulation causes os command injection. This vulnerability is regist…
vuldb
A vulnerability described as problematic has been identified in Browserify pbkdf2 up to 3.1.6. Affected is the function pbkdf2Sync/pbkdf2 of the file lib/sync.js of the component JavaScript Fallback. The manipulation of…
vuldb
A vulnerability marked as problematic has been reported in Red Hat Enterprise Linux. This impacts an unknown function of the component Flatpak. The manipulation leads to path traversal. This vulnerability is listed as C…
vuldb
A vulnerability labeled as critical has been found in LimeSurvey 7.3.0. This affects an unknown function of the component REST Survey Patching Endpoint. Executing a manipulation can lead to improper authorization. This …
vuldb
A vulnerability identified as critical has been detected in Bitwarden Server 1.35.1/2026.4.0/2026.4.1. The impacted element is the function User_ReadBySsoUserOrganizationIdExternalId of the component SSO Login. Performi…
vuldb
A vulnerability categorized as problematic has been discovered in htplugins HT Contact Form Plugin up to 2.10.2 on WordPress. The affected element is an unknown function. Such manipulation leads to cross site scripting.…
vuldb
A vulnerability was found in GestSup up to 3.2.61. It has been rated as problematic. Impacted is an unknown function of the component IMAP OAuth connector. This manipulation causes cross site scripting. The identificati…
vuldb
A vulnerability was found in GestSup up to 3.2.61. It has been declared as problematic. This issue affects some unknown processing of the component IMAP Login Connector. The manipulation results in cross site scripting.…
vuldb
A vulnerability was found in GestSup up to 3.2.61. It has been classified as problematic. This vulnerability affects unknown code of the file thread.php. The manipulation of the argument threadedit leads to improper aut…
vuldb
A vulnerability was found in gz-yami mall4j up to 4.0 and classified as problematic. This affects an unknown part of the component FileController. Executing a manipulation can lead to cross site scripting. This vulnerab…
vuldb
A vulnerability has been found in gz-yami mall4j up to 4.0 and classified as problematic. Affected by this issue is the function checkDelivery of the file A08_delivery_check_anonymous.py of the component DeliveryControl…
vuldb
A vulnerability, which was classified as critical, was found in gz-yami mall4j up to 4.0. Affected by this vulnerability is an unknown functionality of the file A05_sys_menu_missing_perm.py of the component Session Auth…
vuldb
A vulnerability, which was classified as problematic, has been found in gz-yami mall4j up to 4.0. Affected is an unknown function of the file A04_prodcomm_delete_anonymous.py of the component ProdCommController. This ma…
vuldb
A vulnerability classified as critical was found in gz-yami mall4j up to 4.0. This impacts an unknown function of the component Token Refresh. The manipulation results in session expiration. This vulnerability is report…
vuldb
A vulnerability classified as critical has been found in gz-yami mall4j up to 4.0. This affects the function updatePwd of the file /user/updatePwd of the component Password Reset. The manipulation of the argument Userna…
vuldb
A vulnerability described as problematic has been identified in gz-yami mall4j up to 4.0. The impacted element is an unknown function of the file /user/addr/page of the component UserAddrController. Executing a manipula…
vuldb
A vulnerability marked as critical has been reported in Zephyr Project Zephyr up to 4.4.1. The affected element is the function zsock_accepted_cb/zsock_received_cb/zsock_connected_cb/zsock_close_ctx of the file subsys/n…
vuldb
A vulnerability labeled as problematic has been found in Zephyr Project Zephyr up to 4.4.1. Impacted is the function mcumgr_serial_extract_len of the file subsys/mgmt/mcumgr/transport/src/serial_util.c of the component …
vuldb
A vulnerability identified as critical has been detected in Zephyr Project Zephyr up to 4.4.x. This issue affects the function parse_write_op of the file subsys/net/lib/lwm2m/lwm2m_message_handling.c of the component Lw…
vuldb
A vulnerability categorized as problematic has been discovered in Google Angular. This vulnerability affects the function forcequirks of the file lib/HTMLParser.js of the component HTML Parser. The manipulation results …
vuldb
A vulnerability was found in Nginx Proxy Manager up to 2.16.0. It has been rated as critical. This affects an unknown part. The manipulation of the argument advanced_config leads to improper privilege management. This v…
vuldb
A vulnerability was found in cle-b httpdbg up to 2.2.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Web Interface. Executing a manipulation can lead to cros…
vuldb
A vulnerability was found in Nginx Proxy Manager up to 2.16.0. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper restriction…
vuldb
A vulnerability was found in amir20 Dozzle up to 11.1.1 and classified as problematic. Affected is an unknown function of the component Log Download Endpoint. Such manipulation leads to path traversal. This vulnerabilit…
vuldb
A vulnerability has been found in ZoneMinder up to 1.37.x and classified as problematic. This impacts the function output_file of the component Files View. This manipulation of the argument path causes path traversal. T…
vuldb
A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.8.3. This affects an unknown function of the component getCurrentAttrViewImages. The manipulation results in improper authori…
vuldb
A vulnerability, which was classified as problematic, has been found in ZoneMinder up to 1.38.3. The impacted element is the function index of the component FramesController. The manipulation leads to improper access co…
vuldb
A vulnerability classified as critical was found in Siyuan Note SiYuan up to 3.8.3. The affected element is an unknown function of the file siyuan.db of the component Block Query Embed. Executing a manipulation can lead…
vuldb
A vulnerability classified as problematic has been found in Cotonti up to 1.0.0. Impacted is an unknown function of the file admin.users.php. Performing a manipulation results in cross-site request forgery. This vulnera…
vuldb
A vulnerability described as critical has been identified in ZoneMinder. This issue affects the function RemoteCameraHttp::GetResponse of the component HTTP Response Parser. Such manipulation leads to buffer overflow. T…
vuldb
A vulnerability marked as critical has been reported in Open Source Robotics Robot Operating System. This vulnerability affects the function eval of the component Hz Verb. This manipulation of the argument filter causes…
vuldb
A vulnerability labeled as problematic has been found in NestJS Nest up to 11.2.3/12.0.1. This affects the function ServerTCP#handleMessage/ServerRMQ#handleMessage of the component TCP Transport/RabbitMQ Transport. The …
vuldb
A vulnerability identified as problematic has been detected in Laravel up to 12.68.x/13.29.x. Affected by this issue is some unknown functionality of the component Exception Debug Pages. The manipulation leads to cross …
vuldb
A vulnerability categorized as problematic has been discovered in Red Hat Enterprise Linux. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to permission issues. This vulner…
vuldb
A vulnerability was found in Red Hat Enterprise Linux. It has been rated as critical. Affected is an unknown function of the component System Helper. Performing a manipulation results in permission issues. This vulnerab…
vuldb
A vulnerability was found in Facebook Proxygen 2024.10.28.00. It has been declared as critical. This impacts the function WebTransportImpl::terminateSessionStreams of the component WebTransport Session Streams. Such man…
vuldb
A vulnerability was found in Red Hat Enterprise Linux. It has been classified as problematic. This affects an unknown function of the file .desktop of the component Vendor Extension Keys. This manipulation causes denial…
vuldb
A vulnerability was found in Facebook Proxygen 2026.07.20.00 and classified as critical. The impacted element is the function HTTPTransaction::onWebTransportUniStream/HTTPTransaction::onWebTransportBidiStream of the com…
vuldb
A vulnerability has been found in Facebook Proxygen 2026.07.20.00 and classified as critical. The affected element is the function QuicWtSession::closeSession of the component Quic Session. The manipulation leads to use…
vuldb
A vulnerability, which was classified as problematic, was found in juliangruber brace-expansion up to 1.1.18/2.1.4/3.0.6/5.0.9. Impacted is the function parseCommaParts of the component Comma Parts. Executing a manipula…
vuldb
A vulnerability, which was classified as critical, has been found in Wind River Systems VxWorks 25.03. This issue affects some unknown processing of the component Process Management Subsystem. Performing a manipulation …
vuldb
A vulnerability classified as problematic was found in jpadilla PyJWT up to 2.13.x. This vulnerability affects the function RSAAlgorithm.from_jwk of the file jwt/api_jwk.py of the component PyJWKSet. Such manipulation l…
vuldb