Samba vulnerability CVE-2017-12163. Security Advisory. Security Advisory Description. ** RESERVED ** This candidate ...
More info:
https://support.f5.com/csp/article/K00183056
OpenSSL vulnerability CVE-2018-0739. Security Advisory. Security Advisory Description. Constructed ASN.1 types with ...
More info:
https://support.f5.com/csp/article/K08044291
OpenSSL vulnerability CVE-2018-0733. Security Advisory. Security Advisory Description. Because of an implementation ...
More info:
https://support.f5.com/csp/article/K62695363
Project: Drupal coreDate: 2018-March-28Security risk: Highly critical 22∕25 AC:None/A:None/CI:All/II:All/E:Proof/TD:DefaultVulnerability: Remote Code Execution Description: CVE: CVE-2018-7600A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.The security team has written an FAQ about this
More info:
https://www.drupal.org/sa-core-2018-002
Memcached vulnerability CVE-2018-1000115. Security Advisory. Security Advisory Description. Memcached version 1.5 ...
More info:
https://support.f5.com/csp/article/K63525027
PHP vulnerability CVE-2016-5768. Security Advisory. Security Advisory Description. Double free vulnerability in the ...
More info:
https://support.f5.com/csp/article/K95432245
The Shopify Application Security Team reported that ruby-loofah, ageneral library for manipulating and transforming HTML/XML documents andfragments, allows non-whitelisted attributes to be present in sanitizedoutput when input with specially-crafted HTML fragments. This mightallow to mount a code injection attack into a browser consumingsanitized output.
More info:
https://www.debian.org/security/2018/dsa-4171
Project: Drupal coreDate: 2018-March-28Security risk: Highly critical 24∕25 AC:None/A:None/CI:All/II:All/E:Exploit/TD:DefaultVulnerability: Remote Code Execution Description: CVE: CVE-2018-7600A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.The security team has written an FAQ about this
More info:
https://www.drupal.org/sa-core-2018-002
Apache mod_http2 vulnerability CVE-2018-1302. Security Advisory. Security Advisory Description. When an HTTP/2 stream ...
More info:
https://support.f5.com/csp/article/K11509465