OpenSSH Username Enumeration

CVE-2018-11769: Apache CouchDB Remote Code Execution ( Versions 1.x and ≤2.1.2)

Back To The Future: Unix Wildcards Gone Wild

Confirmed: Speculative register leakage from lazy FPU context switching

AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

oss-sec: Go programming language invalid modular exponentiation result (Exp() in math/big pkg)

Vaadin Javascript Injection

CVE-2017-8301: TLS verification vulnerability in LibreSSL 2.5.1 – 2.5.3

Multiple Vulnerabilities in ASUS Routers

Linux kernel: stack buffer overflow with controlled payload in get_options() function

Linux kernel: CVE-2017-6074: DCCP double-free vulnerability (local root)

Linux panic on fragemented IPv6 traffic (icmp6_send)

Multiple vulnerabilities in RPM – and a rant

Forwarding issues related to MACs starting with 4 or 6

CVE-2016-8655 Linux af_packet.c race condition (local root)

SSL Death Alert: OpenSSL (CVE-2016-8610)

GNU tar extract pathname bypass

Deep down the certificate pinning rabbit hole of "Tor Browser Exposed"

CVE-2016-6210: Opensshd user enumeration

Logic security flaw in TP-LINK - tplinklogin.net

oss-sec: CVE request - Go

Server and Client RCE in Git version 2.7.1 and below

SSH Backdoor found in Fortinet firewalls

Qualys Security Advisory – LibreSSL

Complete failure of Oracle security response (2005)

Xen HVM Guest Escape Through CDROM Driver Heap Overflow (CVE-2015-5154)

OpenSSH vulnerability

Microsoft Office – OLE Packager allows code execution in all Office versions

CVE-2015-1328: incorrect permission checks in overlayfs, ubuntu local root

Sourceforge Hijacks the Nmap Sourceforge Account

More →