July 2024 - Page 56 of 107

FreeBSD 14 — chromium-npapi — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — chromium-npapi — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: chromium — multiple vulnerabilities Related CVEs: CVE-2015-1212 CVE-2015-1213 CVE-2015-1214 CVE-2015-1215 CVE-2015-1216 CVE-2015-1217 CVE-2015-1218 CVE-2015-1219  +12 more Upstream summary: Google Chrome Releases reports: 5 security fixes in this release, including: [698622] […]

Read more
Debian 12 — nvidia-graphics-drivers — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — nvidia-graphics-drivers — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-5379 CVE-2012-0946 CVE-2012-0951 CVE-2012-0952 CVE-2012-0953 CVE-2012-4225 CVE-2013-0131 CVE-2013-5986  +12 more Upstream summary: The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and […]

Read more
Alpine Linux 3.18 — gitolite — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux 3.18

Alpine Linux 3.18 — gitolite — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.18 / fixed in 3.6.11-r0 📖 ~4 min read  •  Source: Alpine secdb entry — gitolite 3.6.11-r0 Related CVEs: CVE-2018-20683 Upstream summary: Alpine main repository for vv3.18 ships gitolite 3.6.11-r0 which addresses CVE-2018-20683. Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 13 — putty-nogtk — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — putty-nogtk — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 July 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: putty — multiple security vulnerabilities Related CVEs: CVE-2020-14002 CVE-2023-48795 CVE-2024-31497 Upstream summary: Simon Tatham reports: These features are new in PuTTY 0.84: Security issue: fixed a remotely triggerable double-free in […]

Read more
NetBSD 10.0 — py-postgresql — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — py-postgresql — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2009-2940 Upstream summary: pkgsrc audit-packages flagged py{15,20,21,22,23,24,25,26,27,31}-postgresql<4.0 for vulnerability class 'sql-injection'. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2940 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
NetBSD 10.0 — postgresql91-server — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — postgresql91-server — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2013-0255 CVE-2016-5423 Upstream summary: pkgsrc audit-packages flagged postgresql91-server<9.1.5 for vulnerability class 'multiple-vulnerabilities'. Reference: http://www.postgresql.org/about/news/1407/ Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
FreeBSD 14 — openjpeg — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openjpeg — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenJPEG — integer overflow Related CVEs: CVE-2012-3358 CVE-2012-3535 CVE-2013-1447 CVE-2013-4289 CVE-2013-4290 CVE-2013-6045 CVE-2013-6052 CVE-2013-6053  +9 more Upstream summary: NVD reports: In OpenJPEG 2.3.0, there is an integer overflow vulnerability in […]

Read more
FreeBSD 14 — py311-suds — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py311-suds — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-suds — vulnerable to symlink attacks Related CVEs: CVE-2013-2217 Upstream summary: SUSE reports: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries […]

Read more
NetBSD 10.0 — magento — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — magento — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2015-6497 CVE-2016-4010 CVE-2014-9758 CVE-2016-10704 CVE-2018-5301 CVE-2019-7139 CVE-2020-9690 CVE-2020-9692  +6 more Upstream summary: pkgsrc audit-packages flagged magento-[0-9]* for vulnerability class 'multiple-vulnerabilities'. Reference: http://blog.checkpoint.com/2015/04/20/analyzing-magento-vulnerability/ Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 14 — py37-dparse — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py37-dparse — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-dparse — REDoS vulnerability Related CVEs: CVE-2022-39280 Upstream summary: yeisonvargasf reports: dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is […]

Read more
CHAT