Skip to content
Index
  • About
  • Articles
  • Radar
  • Contact

Radar

A personal hobby project. Radar aggregates security advisories from CISA, Zero Day Initiative and CERT-EU and adds short editorial highlights on what I find notable from a European infrastructure perspective — not a threat-intel service, not exhaustive, just what catches my eye.

All (617) CISA (245) ZDI (357) CERT-EU (15)
  • ZDI 2026-07-23

    ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS…

    Read more →
  • ZDI 2026-07-23

    ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in…

    Read more →
  • ZDI 2026-07-23

    ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a…

    Read more →
  • ZDI 2026-07-23

    ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a…

    Read more →
  • ZDI 2026-07-23

    ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability

    This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the…

    Read more →
  • ZDI 2026-07-23

    ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…

    Read more →
  • ZDI 2026-07-21

    ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-21

    ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-405: X.Org Server GLX Extension Use-After-Free Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-407: X.Org Server PCF Font Parsing Heap-based Buffer Overflow Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-408: X.Org Server ComputeScaledProperties Heap-based Buffer Overflow Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-411: NVIDIA NVTabular Pickle File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NVTabular. User interaction is required to exploit this vulnerability in that the target must visit a malicious…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. User interaction is required to exploit this vulnerability in that the target must visit a…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability

    This vulnerability allows remote attackers to execute web requests with a target user's privileges on affected installations of Microsoft SharePoint. User interaction is required to exploit this vulnerability in…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud. An attacker must first obtain the ability to execute low-privileged code on the target system in order…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud Desktop Application. An attacker must first obtain the ability to execute low-privileged code on the…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-421: Cisco Identity Services Engine validFileNameOrPath Directory Traversal Information Disclosure Vulnerability

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-422: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability

    This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenSSL. User interaction is required to exploit this vulnerability in that the target must make a request to a…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenSSL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability

    This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability, but only systems…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-430: MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability

    This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability

    This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability

    This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability

    This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerability

    This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-441: dnsmasq DNS Response Heap-based Buffer Overflow Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-442: Linux Kernel CAN ISO-TP Protocol Race Condition Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

    Read more →
  • ZDI 2026-07-15

    ZDI-26-404: Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DTM Soft. User interaction is required to exploit this vulnerability in that the target must visit a…

    Read more →
  • ZDI 2026-07-08

    ZDI-26-398: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. Authentication is not required to exploit this vulnerability. The ZDI…

    Read more →
  • ZDI 2026-07-08

    ZDI-26-399: (0Day) (Pwn2Own) Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is not required to exploit this vulnerability. The…

    Read more →
  • ZDI 2026-07-08

    ZDI-26-400: (0Day) AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability

    This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in…

    Read more →
  • ZDI 2026-07-08

    ZDI-26-401: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability

    The vulnerability requires local code execution to trigger a denial-of-service condition via link following in AnyDesk.

    Read more →
  • ZDI 2026-07-08

    ZDI-26-402: (0Day) Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability

    The vulnerability involves link following in Glary Utilities that can lead to local privilege escalation.

    Read more →
  • ZDI 2026-07-08

    ZDI-26-403: (0Day) Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability

    This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating…

    Read more →
  • ZDI 2026-06-24

    ZDI-26-366: Fuji Electric Tellus pcid64 Driver File APIs Exposed Dangerous Method Arbitrary File Deletion Vulnerability

    The vulnerability stems from exposed driver file APIs in Fuji Electric Tellus pcid64 that can be abused to delete arbitrary files.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-367: Fuji Electric Tellus pcid64 Driver Registry APIs Exposed Dangerous Method Local Privilege Escalation Vulnerability

    The Fuji Electric Tellus pcid64 driver exposes registry APIs that can be exploited by local attackers for privilege escalation.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-368: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability

    The vulnerability involves a SQL injection in Quest NetVault Backup's NVBUDashboard that can lead to remote code execution, with authentication bypass possible.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-369: Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability

    The vulnerability enables authentication bypass via cross-site scripting, requiring user interaction such as visiting a malicious page.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-370: Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability

    The vulnerability involves an SQL injection in Quest NetVault Backup's NVBURASDevice that can lead to remote code execution, with authentication bypass possible.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-371: Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability

    Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-372: Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability

    Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-373: Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability

    Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-374: Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability

    Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-375: Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability

    Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-376: Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability

    Authentication is required to exploit the vulnerability, but the advisory notes the authentication mechanism can be bypassed.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-377: Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability

    The vulnerability enables authentication bypass via cross-site scripting in Quest NetVault Backup's viewclient component, requiring user interaction.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-378: ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability

    Authentication is required to exploit this directory traversal vulnerability leading to arbitrary file deletion in ATEN Unizon.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-379: ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability

    Authentication is required to exploit this directory traversal vulnerability in ATEN Unizon's uploadSSL functionality.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-380: ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability

    The vulnerability enables unauthenticated remote attackers to disclose sensitive information via a directory traversal in the writeFileToHttpServletResponse function.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-381: ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability

    The vulnerability involves a directory traversal in the restoreDB functionality of ATEN Unizon, requiring authentication for exploitation.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-382: ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability

    The vulnerability requires authentication and involves a directory traversal in the ImportDeviceList function of ATEN Unizon, potentially leading to remote code execution.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-383: ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability

    The vulnerability requires authentication to exploit and affects the doCryptoHugeFileToFile function in ATEN Unizon.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-384: MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability

    The vulnerability requires user interaction, such as visiting a malicious page or opening a malicious file, to trigger remote code execution.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-385: Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability

    The vulnerability requires authentication but allows remote code execution via a file upload command injection in the Unraid Web Server.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-386: Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability

    Authentication is required to exploit the command injection vulnerability in the Unraid Web Server's ToggleState function.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability

    The vulnerability in Oracle PeopleSoft's HttpListeningConnector permits unauthenticated remote attackers to trigger arbitrary server-side requests.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability

    The vulnerability involves deserialization of untrusted data in Oracle PeopleSoft's HubMBeanPersistance component, with authentication bypass possible despite requiring login.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution Vulnerability

    The advisory notes authentication is required but can be bypassed, which may expand the pool of potential attackers despite the need for initial credentials.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-390: X.Org Server Font Alias Stack-based Buffer Overflow Privilege Escalation Vulnerability

    The vulnerability is a stack-based buffer overflow in X.Org Server's font alias handling, which can be triggered locally to escalate privileges.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-391: X.Org Server miSyncDestroyFence Use-After-Free Privilege Escalation Vulnerability

    A use-after-free in X.Org Server's miSyncDestroyFence function may allow local privilege escalation.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-392: X.Org Server Xkb Key Types Stack-based Buffer Overflow Privilege Escalation Vulnerability

    A stack-based buffer overflow in X.Org Server's Xkb key types can allow local privilege escalation.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-393: X.Org Server SetMap Request Stack-based Buffer Overflow Privilege Escalation Vulnerability

    A stack-based buffer overflow in X.Org Server's SetMap request can enable local privilege escalation.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-394: X.Org Server FreeCounter Use-After-Free Privilege Escalation Vulnerability

    The vulnerability is a use-after-free in X.Org Server's FreeCounter function, potentially enabling local privilege escalation.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-395: X.Org Server SyncChangeCounter Use-After-Free Privilege Escalation Vulnerability

    A use-after-free in X.Org Server's SyncChangeCounter function may allow local privilege escalation.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-396: X.Org Server ChangeDrawableAttributes Out-Of-Bounds Read Information Disclosure Vulnerability

    The vulnerability is a local out-of-bounds read in X.Org Server's ChangeDrawableAttributes function, potentially disclosing sensitive information.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-397: X.Org Server CreateSaverWindow Use-After-Free Information Disclosure Vulnerability

    The vulnerability involves a use-after-free in the CreateSaverWindow function, potentially disclosing sensitive information to local attackers.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-361: Adobe Acrobat Reader DC Field signatureInfo Use-After-Free Remote Code Execution Vulnerability

    A use-after-free vulnerability exists in Adobe Acrobat Reader DC related to the handling of the 'signatureInfo' field, which could lead to remote code execution.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-362: Oracle VirtualBox VMSVGA Stack-based Buffer Overflow Local Privilege Escalation Vulnerability

    The vulnerability is a stack-based buffer overflow in Oracle VirtualBox's VMSVGA component, requiring high-privileged code execution in the guest system to trigger.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-363: Docker MCP Plugin OCI Image Label Parsing Argument Injection Remote Code Execution Vulnerability

    The vulnerability requires user interaction through referencing a malicious Docker image via a docker URI scheme.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-364: FlowiseAI Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

    The vulnerability in FlowiseAI Flowise CSV Agent permits remote code execution without authentication.

    Read more →
  • ZDI 2026-06-24

    ZDI-26-365: FlowiseAI Flowise CSV Agent customReadCSV Code Injection Remote Code Execution Vulnerability

    The advisory notes that authentication is required but can be bypassed, which may expand the pool of potential attackers despite the need for initial access.

    Read more →
  • ZDI 2026-06-11

    ZDI-26-356: Apache HTTP Server mod_proxy_ajp Out-Of-Bounds Read Information Disclosure Vulnerability

    The vulnerability requires prior compromise of an AJP backend to enable information disclosure via mod_proxy_ajp.

    Read more →
  • ZDI 2026-06-11

    ZDI-26-357: Allegra exportReport Directory Traversal Information Disclosure Vulnerability

    The vulnerability requires authentication and could allow remote information disclosure via a directory traversal in the exportReport functionality.

    Read more →
  • ZDI 2026-06-11

    ZDI-26-358: Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability

    The vulnerability requires user interaction, such as visiting a malicious page or opening a malicious file, to trigger cross-site scripting.

    Read more →
  • ZDI 2026-06-11

    ZDI-26-359: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability

    The vulnerability involves a numeric truncation issue in Samsung rlottie that can lead to remote code execution when the library processes input.

    Read more →
  • ZDI 2026-06-11

    ZDI-26-360: MATE Desktop Atril Document Viewer EPUB File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    The vulnerability is a heap-based buffer overflow in Atril Document Viewer triggered by parsing a malicious EPUB file.

    Read more →
  • ZDI 2026-06-10

    ZDI-26-355: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    The vulnerability is a use-after-free in Adobe Acrobat Reader DC related to annotation handling, requiring user interaction to trigger.

    Read more →
  • ZDI 2026-06-10

    ZDI-26-328: ASUS MyASUS Origin Validation Error Local Privilege Escalation Vulnerability

    The vulnerability stems from an origin validation error in ASUS MyASUS that may allow local privilege escalation.

    Read more →
  • ZDI 2026-06-09

    ZDI-26-347: Adobe Acrobat Reader DC Multimedia Rendition Use-After-Free Remote Code Execution Vulnerability

    The vulnerability is triggered by user interaction with a malicious file or page, indicating delivery likely depends on social engineering.

    Read more →
  • ZDI 2026-06-09

    ZDI-26-348: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    The vulnerability is a use-after-free in Adobe Acrobat Reader DC related to annotation handling, requiring user interaction to trigger.

    Read more →
Knut Michael Haugland © 2026
  • LinkedIn
  • GitHub
  • Contact
  • Atom