LinuxSecurity.com
OpenOffice Vulnerability Can Run Code From Malicious Documents
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Kategorie: Hacking & Security
OpenOffice Vulnerability Can Run Code From Malicious Documents
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Kategorie: Hacking & Security
Apache Thrift 0.25.0 Adds Memory Limits for Network Messages
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
Kategorie: Hacking & Security
Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
Kategorie: Hacking & Security
OpenSSL Vulnerability Can Leak Server Memory Through DTLS
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
Kategorie: Hacking & Security
LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution features in some AI gateway deployments.
Kategorie: Hacking & Security
Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Kategorie: Hacking & Security
Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Kategorie: Hacking & Security
Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memory.
Kategorie: Hacking & Security
Apache Camel Vulnerability Can Expose Files and Internal Services
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal services.
Kategorie: Hacking & Security
Proposed Linux IPsec Fix Addresses IP-TFS Packet Cleanup Race
Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic patterns harder to infer.
Kategorie: Hacking & Security
Proposed Linux FastRPC Fix Addresses Shared-Buffer Cleanup Race
Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.
Kategorie: Hacking & Security
Proposed Linux QNX6 Fixes Address Filesystem Memory Errors
Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.
Kategorie: Hacking & Security
LightLLM Profiling Flaw Allows Code Execution Without a Login
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring performance.
Kategorie: Hacking & Security
ModSecurity Updates Fix WAF Bypasses on Linux Web Servers
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without being inspected as intended.
Kategorie: Hacking & Security
Linux Device Driver Fix Prevents Clock Lookups From Reading Freed Memory
A Linux device driver fix closes a use-after-free risk in the AC100 real-time clock (RTC) driver.
Kategorie: Hacking & Security
Flatpak Vulnerability Fixes Protect Linux Host Files and Processes
Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.
Kategorie: Hacking & Security
Linux Storage Fix Stops Cleanup From Freeing the Same Object Twice
A Linux flash-storage fix prevents a double free, in which the kernel releases the same object twice during device setup.
Kategorie: Hacking & Security
Apache Karaf Flaws Can Let Limited Users Run Commands or Rewrite Files
Apache released Karaf 4.4.12 on September 27, 2026, to fix three authorization flaws in its Java server runtime.
Kategorie: Hacking & Security
Command Injection Flaw in shell-quote Can Execute Linux Commands
The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.
Kategorie: Hacking & Security



