A security vulnerability has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The supported versions confirmed to be affected are 12.2.1.4.0 and 14.1.2.0.0.This flaw is easily exploitable: an attacker does not need any login credentials to carry out an attack, as long as they can send standard ...
Continue reading
A security vulnerability has been identified in DD-WRT, a popular firmware used by many home and small business network routers. The flaw is a stack-based buffer overflow, a type of memory error, that impacts the router's UPnP (Universal Plug and Play) feature, a tool designed to help devices on a local network automatically discover and connect ...
Continue reading
A security vulnerability has been identified in Langflow, a no-code tool for building AI workflows that some website owners run on their hosting accounts. The flaw is classified as an "inclusion of functionality from untrusted control sphere" issue, meaning the software can accidentally pull in and run unvetted, external code from sources outside ...
Continue reading