Radar
A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.
-
ZDI-26-116: TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The vulnerability requires local access and low-privileged code execution to exploit. The advisory notes a CVSS score of 7.0.
Read more → -
ZDI-26-117: RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability
A local attacker with low privileges can exploit this vulnerability to disclose sensitive information from RustDesk Client for Windows installations.
Read more → -
ZDI-26-118: GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability
The vulnerability stems from uninitialized memory usage during PGM file parsing in GIMP, which could lead to remote code execution if a user opens a malicious file.
Read more → -
ZDI-26-119: GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write during XWD file parsing in GIMP, requiring user interaction to trigger.
Read more → -
ZDI-26-120: GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is triggered by parsing a malicious ICNS file, leading to a heap-based buffer overflow in GIMP.
Read more → -
ZDI-26-121: GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write during XWD file parsing in GIMP, which could allow remote code execution if a user opens a malicious file.
Read more → -
ZDI-26-122: PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
PDF-XChange Editor contains a local privilege escalation vulnerability in its TrackerUpdate component. Exploitation requires prior low-privileged code execution on the target system.
Read more → -
ZDI-26-106: Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
The vulnerability involves an out-of-bounds write during CATPART file parsing in Autodesk AutoCAD, requiring user interaction for exploitation.
Read more → -
ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability requires user interaction via opening a malicious file or visiting a malicious page.
Read more → -
ZDI-26-096: Dassault Systèmes eDrawings Viewer EPRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
The vulnerability requires user interaction via a malicious file or page. A heap-based buffer overflow enables remote code execution.
Read more → -
ZDI-26-097: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
The vulnerability requires prior execution of high-privileged code on the guest. The heap-based buffer overflow occurs in the VMSVGA component.
Read more → -
ZDI-26-098: Oracle VirtualBox VMSVGA Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability requires prior high-privileged code execution on a guest system to escalate privileges. The ZDI assigned a CVSS rating of 8.2.
Read more → -
ZDI-26-099: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability
Requires prior high-privileged code execution on the guest system. Exploitation is constrained to a race condition within the VMSVGA component.
Read more → -
ZDI-26-100: Oracle VirtualBox LsiLogic Uninitialized Memory Information Disclosure Vulnerability
The vulnerability requires a local attacker with high-privileged guest code execution to exploit. It targets Oracle VirtualBox's LsiLogic SCSI controller component.
Read more → -
ZDI-26-101: Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability
The vulnerability requires local execution of high-privileged code on a guest system. The CVSS rating is 6.0.
Read more → -
ZDI-26-102: Oracle VirtualBox VMSVGA Out-Of-Bounds Write Local Privilege Escalation Vulnerability
The vulnerability requires an attacker to already have high-privileged code execution on the guest system. The exploit targets the VirtualBox VMSVGA virtual device.
Read more → -
ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability
This vulnerability requires an attacker to already have high-privileged code execution on the guest system. The exploit targets the VMSVGA virtual graphics component within Oracle VirtualBox.
Read more → -
ZDI-26-104: Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability
The vulnerability is triggered by parsing a malicious DCM file, requiring user interaction to open the file or visit a malicious page.
Read more → -
ZDI-26-105: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
The vulnerability affects the MLflow Tracking Server's Artifact Handler, allowing remote code execution via directory traversal without authentication.
Read more →
Page 7 of 7 · 619 advisories