Buscar noticias

Ctrl/Cmd para multiselección
Total: 3976

USN-8477-1 fixed a vulnerability in tar. The update introduced a regression that could cause tar to fail to extract certain valid files. This update fixes the problem. Original advisory details: It was discovered that tar incorrectly ha…

Ubuntu 2026-07-16 20:05 UTC · 2026-07-16 17:05 -03

Jay Neiva and Mauro Carrillo discovered that Authlib did not properly validate cryptographic keys embedded in JWT headers. An attacker could possibly use this issue to forge trusted tokens, resulting in authentication and authorization byp…

Ubuntu CVE-2026-27962CVE-2026-28490CVE-2026-28498CVE-2026-41425 CVSS 9.1 2026-07-16 17:44 UTC · 2026-07-16 14:44 -03

It was discovered that the Net::IMAP client in Ruby did not properly sanitize Symbol arguments passed to IMAP commands. A remote attacker controlling a malicious IMAP server, or able to influence command arguments, could use this to inject…

Ubuntu CVE-2026-42258CVE-2026-27820 CVSS 9.8 2026-07-16 13:54 UTC · 2026-07-16 10:54 -03

Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer token in command-line arguments when validating APT credentials. A local attacker could possibly use this issue to obtain sensitive information and gain unauthorized …

Ubuntu CVE-2026-9494CVE-2026-11386CVE-2026-12391 CVSS 9.0 2026-07-16 12:59 UTC · 2026-07-16 09:59 -03