Git: Malicious repositories can execute remote code while cloning

Baron Samedit: Heap-based buffer overflow in Sudo (CVE-2021-3156)

Pam 1.5.0 has a auth bypass under some conditions

Linux Kernel Runtime Guard (LKRG) in a nutshell

Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

Remote Code Execution in qmail

Short notes on qmail security guarantee

LPE and RCE in OpenSMTPD's default install (CVE-2020-8794)

LPE and RCE in OpenSMTPD's default install (CVE-2020-8794) (exploit embargo lifted)

LPE and RCE in OpenBSD OpenSMTPD (CVE-2020-7247)

Authentication Vulnerabilities in OpenBSD

Local Privilege Escalation in OpenBSD's dynamic loader (CVE-2019-19726)

Multiple vulnerabilities fixed in Git

Critical vulnerability in Dovecot and Pigeonhole

ClamAV: Denial of Service through "better ZIP Bomb"

RCE through open PHP-FPM ports

Data exfiltration with FPM servers (HHVM and rarely PHP)

SACK Panic – CVE-2019-11477 – Multiple TCP-based remote denial of service issues

CVE-2019-10149 Exim 4.87 to 4.91

DLL injection in Go < 1.12.2 [CVE-2019-9634] not in 1.12.2 release notes

System Down: A systemd-journald exploit

CVE-2018-5407: new side-channel vulnerability on SMT/Hyper-Threading architectures

About OpenSSH "user enumeration" / CVE-2018-15473

OpenSSH user enumeration

A new Intel CPU bug is revealed

Procps-ng Audit Report (Local Privilege Escalation in libprocps)

musl - Re: Re: #define __MUSL__ in features.h

yescrypt 1.0.0 - modern KDF and password hashing scheme

Review of LibVNCServer/vncterm proxmox/vncterm proxmox/spiceterm xenserver/vncterm qemu/ui/console.c

LKRG - Linux Kernel Runtime Guard

More →